



REF ID:A65669 

TOP SECRET 



NATIONAL SECURITY AGENCY 

MECHANIZATION IN SUPPORT 

OF COMINT 
PHASE II 



WARNING 

THIS DOCUMENT CONTAINS 
CODEWORD MATERIAL 

TOP SECRET CONTROL NUMBE R S 3QOV?± 

SK bZzkUdSS 

TOP SECRET 

Declassified and approved for release bvNSA on 08-16-2013 pursuant to E.Q. 1352^ 




MECHANIZATION IN SUPPORT OF COMINT 
PHASE II 

Editors 



H. F, De Francesco 


R/D 


D t L. Hogan 


r/d 


Report Committee 


t 


W, A, Blankinship 


r/d 


H. F. De Francesco 


r/d 


D. L. Hogan 


R/D 


R. A, Leibler 


R/D 


A. J. Levenson 


PROD 


Directed by 


A. B. Clark 


R/D 


J. J, Eachus 


R/D 




I 

I 



PREFACE 



I 

I 

I 

I 

I 

I 
I 
I 

I 



This report contains the results of the second phase of the 
study "Mechanization in Support of COMINT"* It is a somewhat 
detailed statement of what is being done at the present time, and 
attempts to point out the weaknesses of that effort* Phase Three 
will comprise suggestions as to what can be done to eliminate 
these weaknesses. Readers of this document are invited to con'*' 
tribute suggestions for inclusion therein. The fourth and final 
phase will be a considered selection of these proposals, intended 
to form an integrated Research and Development program. 

Chapter A was written by H. F. De Francesco and reviewed 
by O. R. Kirby. Chapter B was written by A. H. Housman and 
E, Fergusson. Mr. O,. R. Kirby also reviewed this chapter. 

W. A. Blankinship wrote the chapter on Traffic Analysis; it was 
refereed by H. L. Conley. The chapter on Weather was written 
by H. F. De Francesco and reviewed by A. W« Kellond and 

L. Schlauch. D. L. Hogan and H. F, De Francesco compiled the 
chapter on Plain Language which was checked by P. A, O'Sullivan. 
The chapter on Machine Ciphers was prepared under the general 
supervision of A. J. Levenson. The section on Hagelin was writ- 
ten by J. E. Bates, Selector Machines by T. A. Evans and 

M. H. Budenback, Sturgeon by G. F, Stahly, Introduction and Sec- 
tion on Enigma by A. J. Levenson. 



The chapter on Hand Systems -was written by R» A. Leibler. 



The final chapter was written by H. F. De Francesco and 

D. L. Hogan. It was edited by M. M. Mathews and A. B, Clark. 

In addition, L, W, Tordella, H. H. Campaigns, A, B, Clark' 
and J. J. Eachus read through selected chapters of this report 
and gave many valuable suggestions as to form and content. 

Many others, whose names are not listed, have freely contri* 
buted both time and talent to the fact finding tasks and editing chores. 
To these people We are especially indebted. 

n 



TOP SECRET EIDER 










f?' ii .1 & 



TABLE OF CONTENTS 



TRAFFIC COLLECTION ACTIVITY -I 



Introduction 



Problems of Collection 



1. Search Problems 



2. Location and Assignment Problems 

3. Budgetary Problems . ....... 

4. Administrative Problems ...... 

5. Technological Problems ...... 



Present and Future ....... 

1. Standardization of Equipment . 

2. Standardization of Operation . 

3. Site Planning and Modification 

4. Operation Requirements . . , 

5. Copy Requirements 

6. Personnel Requirements . . . 



B TRAFFIC COLLECTION ACTIVITY -II 



Introduction 



1. Definition 13 

2. Evaluation 13 

3. Non-Conventional Signals 14 

4. Comments and Recommendations 14 

General Description of Traffic Collection Operation .... 15 

1. Types of Transmissions 15 

2. Nature of Traffic 15 

3. Quantity of Traffic 16 

4. Intercept Facilities 16 




TOP 

TABLE OF CONTENTS (cont'd) 



5. Receipt of Traffic .......... ...... 

a. Page Copy Production • . . . 

b. Sorting and Distribution . » . . » 

III Evaluation of Effectiveness of Current Operations 

1. Technical Evaluation of Elements • •■•••• 

a. Antennas . » • . • 

Coupling Transformers ...... . * • • 

Transmission Line ....... 

\ 

Multicouplers ................ 

Receiving Equipment . ......... «/ 

Recording Equipment 

Demultiplex Equipment • ••••••••/• 

Single -Side -Band ..... ........ 

Morse Operator Analysis (MOA) . , , . . 
Radio Finger Printing (RFP) 



PL 86-36/50 USC 3605 
EO 3.3(h)(2) 

jeage 

. 16 

. 17 

. 17 



b. 

c. 

d. 

e. 

f. 

g» 

h. 

i. 

j. 

k. 

l . 

m, 

n. 






Intercept Sites 



2 . 



Operational Evaluation ....... 

a. Operational Evaluation Criteria 

b. \ Morse 

(1) Manual Morse ........ 

(2) Automatic Morse ...... 

c. Radio Printer 

(1) Russian Service Radioprinter 

( 2 ) 



d. 

e. 



Radio Telephone ... 
Qualifying Statements 



17 

17 

17 

20 

21 

23 

24 
27 
29 

32 

33 
35 



Direction Finding { D/F ) .............. 39 

Automatic Mors'e Translating Equipment ..... 

Positions 



42 

44 

46 

48 

48 

51 

52 

54 

55 

56 
58 
60 
62 








T OP 5 EIDER 

TABLE OF CONTENTS (contMl 

Page 

IV Comments and Recommendations * * v* • •.»•.••.» 63 

1. Level of' Performance . . » • . »..••*..•-» » « 63 

2. Area for Improvement .».»»•»»»»»«»•»*» 64 

3. Liaison • « . • . • '•.>«*..*»..*.. 65 

C TRAFFIC ANALYSIS 

I Introduction ........ 66 

It Description of T/A Data • «...... ....*«»•« 66 

1. Call Signs ....•»••.»»..«»».«»»»».» 67 

2. Message Headings ..•«.•»..**».»«••».» 67 

3. Operator Chatter .»•..*•*»* * . . . * 67 

4* Practice Traffic .»•••..»•••• • •«».*«« 67 

5« Bona Fide Messages ..».**»••» » » • « 68 

III Description of T/A Processes • • . » 68 

1* The Intercept Operation ..••••...•*••*•.» 68 

2. TECSUMS * . . 69 

3. Forwarding ........... 69 

4. Transcription ...... ...... 7# 

a. Radioprinter ....... ......... 7 d 

■ t 

b, Radio Telephone .».*••..»•• 7$ 

c* Other Transmission . . . . • . 70 

5. Identification ...... 71 

6* Editing and Sorting • »••».»•••••...»•.. 71 

7. Analysis . • . .......... 73 

a. Decision , . 73 

b. Evaluation ........ ......... 73 

8. Filing and Storage 74 

IV Magnitude 75 



TOP SECRET EIDER 








TOP SB CREfr^l HDER 

TABLE OF CONTENTS (contM) 



1. Receipt 75 

2. Exploited Material .•*••»*••»»••»•»••.» 76 

3. Non-Exploited Material • »»••»»«•.»*«.»»• -76 

V Comments and Recommendations »«•»••••••..» 76' 

1. Data Handling 76 

2. Electrical Forwarding ...... * . . 77 

3. Filing ., ••••«..••• • «««»•«. ««»«». 78 

4. Other Problems *....«*»•«• • » » . 79 

Table A . . 80 

Table B 81 



D WEATHER 



I 

II 

III 

IV 

V 

VI 

VII 



I 

II 

III 



Introduction ......... 

Interest In Weather . . • » , 
Weather Traffic Flow ... 
Intercept Points and Volumes 
Cryptanalysis ••••*■• 

Traffic Analysis ...... 

Recommendations 

1. T/A and C/A ....... 

2. Speed of forwarding ... 

3. - Intercept 



82 

83 

83 

84 
84 

84 

85 
85 
85 
85 



PL 86-36/50 USC 3605 



E PLAIN LANGUAGE ■ eo 3.3(h)(2) 

Introduction .......... .............. 86 

Sources ........ .... 86 

| [ Communications ... 86 

1. General ...... ...... * .......... ... 86 



TOP SECRET EIDER 











TABLE OF CONTENTS (dont*d) 



-2. Non-Voice 

3. Voice . . 



Page 

87 



4. Intelligence 



International Commercial Radio 

1. General ...... 



2. Intercept Control 

3. Intelligence . . . 



Areas for Mechanization 



F MACHINE SYSTE’MS 



PL 86-36/50 USC 3605 
EO 3.3 (h) (2) 



Introduction 



1. Cipher Machines 

2. Rotor Devices • 



3. Pin Wheel Machines • 94 

a. Hagelin C-38 • • 94 

b. Teletype 95 

4. Other Varieties 96 

5. Exploitation of the ENIGMA 96 

a. Number of Variables 97 

b. Use of a Crib ....... ....'. 98 

c. Message Setting .99 

d. Volume of Effort 99 

6. Use of High Speed Equipment 99 

7. Initial Attacks * • 99 



Pin Wheel Devices 



b. Rotor Devices 



8. Cryptographic Security 102 

The Hagelin Problem 103 

1. Description 103 





TABLE OF CONTENTS (cont*d) 



Page 

2. Weaknesses ............I. 103 

3. Statistical Solution • . . 104 

a. Width Writing . ......... 105 

b. .Parity Attacks 106 

c. Flagging • • 106 

d. Effectiveness df Statistical Attack ...» 107 

e. Cage Recovery . . . . • • » 108 

f. Depth Reading ««.»•«» 109 

g. Recovery of Machine Ffrom Key ’ 109 

4. Placement • . » 110 

a. Crib * 110 

b. Statistical •• 110 

5. Machine Methods .»....» 112 

a. Special Machines 112 

b. Digital Computers 113 

6. Residual Problems . . 114 

7. Current Traffic and Readibility 115 

III The Modified B-211 116 

1. Usage ........... • • . 116 

2. '-Description 117 

♦ 

a. Fractionation. 117 

b. Rotors 118 

c. Steckers 119 

d. Block Diagrams' 119 

e. Motion ............. 120 

3. Machine Methods . 121 

a. FROG . . 121 

b. Computer Program 122 

c. Analogs 122 



TOP SECRET EIDER 




TAB LIT: OF CONTENTS (cont'd) 



Page 



d. Ilandlcsters ..................... 122 

\ 

4. Standard B -211 



IV 



V 



VI 

IX 



1 . 

2 

3 

4 

1 . 

2 



3 



4 

5 



1 . 

2 

3 

4 

5 



Sturgeon .......... * 

, Description ........ > 

. Analysis ........... 

. Machine Methods 'i . . . ,* 

. Usage and Success ..... 

Japanese Machine Systems . . 

\ 

> Usage and Success ..... 

« Key Generation ...... 

a. Beer «... 

b. Purple , 

c. BA . 

. Weaknesses ......»•. 

a. Indicators * 

b. Isologs 

c. Cribs 

d. Wiring . • 

. Complicating Factors . . . 

. Machine Methods 

a. Within Branch 

b. Other .......... 

ENIGMA 



. 123 
12 3 

124 

125 
127 

127 

127 

127 

128 
128 

129 

130 
130 
130 
130 

130 

131 
131 

131 

132 

134 



NOTE: Sections VII and VIII are EO 3.3(h)(2) 



bound separately PL 86-36/50 USC 3605 

Future Machines 135 

, General .......................... 135 

. CX-52 . . . 135 

. ]. 136 

. OMI and TBN - 136 



. Other Developments 



13 b 



TOP SECRET EIDER 





TABLE OF CONTENTS (cont'd) 



Page 

X Comments and Recommendations t t «••>»>< « 137 



G HAND SYSTEMS 

I Introduction .a.. ........ . » . * ........ 1*10 

1. Hand Systems ° 140 

2. Keys 141 

3. Usage • . * » * * • 141 

II Diagnostic Operations «...*.••••..•• .... 142 

1. Need ........... 142 

2. Preliminary ...................... . 142 

3. Identification .......... .»••»»»•••••» 142 

4. Non-Key ........ • «••«».••. » • 143 

5. Key ... . . . 143 

III Exploitation (Non-key) ...» 143 

1. Needs 143 

2. Methods 143 

IV Exploitation (Exploitable Key) 144 

1. General 144 

2. Preliminary Processing 145 

3. Principal Processing 146 

V Exploitation (Non-Exploitable Key) 147 

1. General .......... 147 

2. Depth Location ........ 147 

3. Depth Reading 148 

4. Key Analysis 149 

-VI Comments and Recommendations 149 

1. Rehandling of Traffic 149 



TOP SECRET EIDER 




TABLE OF CONTENTS (cont'd) 



Page 

2. Code Look Up »..•••.*.•• 150 

3. Preliminary Processing. ....»«•»., * . 150 

4. SLED - DEMON , 150 

5. Key> Re-use ....... % ........ ....... 151 

H OTHER SIGNALS 

I Cryptographic Radiation • •*••• ****.....»• 152 

1. Description ......... 152 

2. Potential *•...•.•.•* ....... 152 

II Noise Communications ... 153 

1. Description .... . 153 

, < 

2. Current Effort ..«•••••.. 154 

III Short Signals • 1 154 

1. Description •••••••••••...»•• 154 

2. Current and Projected Effort .............. 155 

IV Ciphony, Cifax and Speech Privacy . 156 

1. Introduction ..... 156 

a. Ciphony 156 

b. Cifax ........ 156 

c. Speech Privacy •..•.••••..«.•»•... 157 

2. Ciphony and Cifax 157 

a. State of COMINT Effort ...... 157 

b. Digitalization of Ciphony 157 

c. Delta Modulation 158 

d. Pulse Code Modulation ............... 158 

e. Vocoder plus PCM 158 

f. Comparative rates 159 

g. Addition of Noise 159 

h. Cifax 160 



TOP SECRET EIDER 




TABLE OF CONTENTS (cont'd) 



t ' 

Page 

- 3. Non-Digital Speech Security 161 

a. Description 161 

| b. Current and Projected Effort 161 

I 

V Facsimile Intercept 162' 

VI Very High-Frequency Intercept (VHF) ........ 164 

VII Ultra High Frequency Ihtercept (UHF) 167 

VIII Comments and Recommendations 170 





A TRAFFIC COLLECTION ACTIVITY -I 

I. INTRODUCTION 

The starting point of NSA's COMINT activity is the collection 
of target countrys* communications Most communicators employ 
radio transmission; others employ messengers, etc. In what 
follows we shall discuss only the intercept of foreign radio com- 
munications and the problems associated with this operation. If 
the communications are not transmitted electrically, we usually are 
not able to intercept them. 

In order to cover the communication links used by Russia, Poland, 
Communist China, and all other target nations of very high or low 
priority, we require a worldwide setup of intercept stations. Presently 
the United States has about 120 sources from which traffic is obtained. 
These sources range from intercept stations containing 100 or more 
positions (a position is a receiver and its associated equipment) to 
very small detachments which operate one or two receivers. Some 
intercept stations are located in very unusual sppts around the world. 

II. PROBLEMS OF COLLECTION 

1. One of the problems of collection is to locate and intercept 
transmissions sent over temporary or newly established communica- 
tion links. The program under which this problem is studied is called 
the General Search Program. Another problem is searching for and 

- 1 - 




JLVJL 



identifying new and unusual ty^es of transmissions. For this prob-"'' 

i 

lem we utilize Technical Search facilities. We differentiate between 
there problems because there is a difference in our approach to them* 
New and unusual types of transmissions such as scatter and noise, 
communications, are presently receiving little attention. The search 
for standard high frequency communications falls under the general 
search program which is PROD's responsibility. The search for 
new and unusual types of transmissions is part of the Technical 
Search program which is R/D’s responsibility and which will be dis- 
cussed in the next chapter. When we can intercept new and unusual 
signals, we usually try to set up an operational inteihcept program 
to collect worthwhile material. 

We also have the problem of developing equipment, new 
techniques, and new methods for intercept. We will touch on this 
problem and give a few examples in what follows, but as a matter of 
information we must point out that target nations sometimes surprise 
us with new and different signals about which we have little or no 
previous knowledge. 

2. In order to have an effective intercept program, we must 
situate and assign our intercept facilities properly and supply them 
with the best equipment available. These axiomatic requirements 
are quite difficult to meet. For instance, we never seem to have 
enough intercept operators, stations, and equipment to cover all 
the targets on the air at any given time. We have to set up priorities 
of coverage whereby the most important targets are covered first. 



" TOP SECRET EIDER 




We then cover as many of the .-less important targets as we can. The 
assignment of intercept stations to specific targets during specific 
periods of time is called "intercept control. 

With reference to the problems of cryptanalysis and traffic anal- 
ysis we find that the collection' effort of the United States leaves much 
to be desired in terms of accuracy, quality of coverage, and the ex- 
tension of the total amount of coverage. 

There are some definite reasons why this happens and why we 
are not able to achieve the ultimate In intercept coverage. These 
reasons will now be discussed. 

First of all we have definite limitations on the locatio,n of inter- 
cept sites. We would like to intercept all of the low-level communi- 
cations emanating from the Moscow area. Unfortunately, we are not 
able to go to Russian territory and set up an intercept station to inter- 
cept this traffic. Nor are we able tp operate, a VHF voice intercept 
installation from ah air field or from aircraft in the vicinity of Moscow. 
For all practical purposes we cannot locate in any part of Russia or 
within the satellite countries. Our only, recourse is to pick locations 
as close to die target as possible and as much "in line" to the signal 
direction as possible. In mpst cases we intercept traffic under non- 
ideal conditions. 

3. Next there are budgetary limitations which prevent us from 
having equipment and personnel' sufficient in number and quality. The 
NSASAB conducted a study on the potential of COMINT to supply early 



3 - 




warning of an impending enemy attack. This board recognized 
the importance of having high quality intercept operators, analysts 
etc. These are the people on whom we must rely to obtain the mater- 
ial from which COMINT is. derived. Most ol’our operators are mili- 
tary personnel many of whom serve for a temporary period and then 
return to civilian life. The permanent military people also remain 
with us in the COMINT activity for a limited period of time and are 
then rotated. We will point out what i9 being done ori this problem 
in the sequel. 

4. We also have some administrative problems. These center on 
the lack of authority we have over field commanders, construction or- 
ganizations, and others who have a say in the actual construction of inter- 
cept sites- and equipment. We must work through a chain of command. 
During this procedure there is a great deal of time lost. Moreover, 

our requirements may not conform with the requirements of the ser- 
vices. As a result there is much time lOBt from the inception to the 
completion of required intercept facilities, wherever modifications, 
new sites, and equipments are necessary. When it is required that a 
specific communications link be intercepted, we would like to get there 
with the equipment and men as soon as possible. At present we are 
not able to modify existing sites or put up new sites within any short 
period of time. 

5. Another problem is that of acquiring the technological "know how" 
to find, identify, and intercept new communication systems as they 

- 4 - 




EO 3.3(h)(2) 

PL 86-36/50 USC 3605 



come on the air. This means that we must employ, or retain under 



contract, the best talent in the communications field so that 



we might 



keep ahead of target countries and be prepared to cope with any com- 
munications system they may employ in the immediate future. In 
the past we were faced with the intercept of manual morse and hand- 
speed morse transmissions in the medium frequency band. Next we 



had the problem of radio-teletype. The result was that most 



of our 



effort was placed on intercept by means of standard radio receivers 
and teletype equipment. Presently the shift has been to higher fre- 
quency transmissions, the ranges being not only the 5 to 30 mega?» * 
cycle range but also the low to ultra-high frequency range. Here we 
require more modern types of intercept equipment. // Recently, the 



Russians have employed aL 



multiplex transmission system. 



This is a 



transmit on 



mltiplex system with which the Russians can 



In addition they 



within a short 



period of time. A complicating cryptanalytic feature is that all chan- 



nels are 



trhile the transmission is on the air. 



As a point of interest, Russia has very good North - South com- 
munication links. We are off to one side trying to pick up this type 
of transmission, and the results are not very heartening. We are 
having difficulties intercepting this material and then trying to produce 
usable page copy from it. Adding to the lack of directivity the fact 
that we are trying to intercept transmissions having a 



- 5 - 






PL 86-36/50 USC 3605 

EO 3.3(h)(2) 

of about one can readily seethat we readly need 

the best technological approach to this intercept problem in terms of 
equipment, personnel, and operating procedures. 

Presently we are dealing with three different intercept operat'idns, 
setups, and procedures. Each Armed Service has its own equipment, 
modes of operation, and setup procedures. Also, differences exist 
within each service; e.g. , ASA stations intercepting hand-apeed 
morse employ different equipment, setup procedures, and modes of 
operations. These differences must be minimized. 



III. PRESENT AND FUT URE EFFORT 

In the preceding paragraphs we have listed some of the major 
problems which face us. Now we shall discuss what we are doing 
to improve the present situation and what we intend to d6 in the 
future. 

1. First of all we are starting a standardization program for 
intercept operation. This does not mean that we intend to make every 
intercept station look like every other intercept station. What we pro* 
pose to do is to design every station so as to obtain maximum efficiency 

and effectiveness in the intercept activity and in the handling of raw 

_ /■ • 

material within that station. Within the Armed Services we wish to 
have ^uniformity among positions performing essentially the same 
-functions. We do not specify -that every service will employ a Collins 
HF receiver and use that receiver to the exclusion of all others. We 



- 6 - 



TOP SECRET EIDER 






two ot ^tonre-e 'standard types of receivers within the sel-- 
toigreT form the same intercept mission, provided that these 
'>» ec^i've r s have equivalent characteristics. 

To accomplish the standardization needed we suggest a procedure 
as follows. First, we establish the types of transmissions with which 
we have to contend. These may be manual morse, voice and high-fre- 
quency transmissions, ultra -high frequency, voice and microwave 
type transmissions, teletype of various sorts, facsimile, or others. 
Then we must determine the type of 'equipment necessary to inter- 
cept these signals. Then we must specify how the equipment should 
be operated. In -particular some questions to be answered are the 
following. How should. the receiver be tuned? What recorders may 
be connected to the different type receivers? What is the best pro- 
cedure for recording the intercept? 

2. After we categorize the types of transmissions and the types 
of equipment best suited to intercept the transmissions, we then have 
to supply operational procedures and information to the intercept 
station. We must determine the number of peopl'e required to do a 
specific job, at a given intercept position at a. given time. 

Our attempt is to emphasize correct operation and production of 
accurate copy of desired targets rather than interception of large vol- 
umes of material. For instance, there may be a frequency range 

over which a target nation transmits extremely valuable information 

v 

but does so infrequently. Here it might pay to guard this frequency 








r-ange even though we obtain only several messages a month. 

B-ecanse of the value of the product, it rtoight require two attendants 
to the position to obtain high quality intercept. Normally these two 
attendants might operate four positions. The results that come off 
the four positions might not be worth much, but too often the tenden- 
cy In the field is to assign the two attendants to the four positions 
rather than to the one position. This is the tendency we are trying 
to overcome and it is one of the administrative problems facing us. 

We propose to prepare minimum standards for all of our major in- 
tercept operations. These standards will give the minimum require- 
ments for satisfactory intercept in terms of equipment, personnel, 
and operating procedures. Stations will not operate below the mini- 
mum standards and most should operate above the standards. 

3. We are also trying to keep ourselves fully informed on modi- 
fications to existing intercept sites and on thf plans for new intercept 
sites. We intend to look at all plans for construction and modifications 
before they take place. We have some examples of intercept installations 
which were improperly modified or designed. In at least one station, 
for example, several antennas were actually cut off the transmission 
lines without affecting the operation of the station. In order to avoid 

1 T 

these errors we need to review proposed plans to ascertain that the 

stations will meet the minimum requirements necessary for satisfac- 

\ 

tory operation. Moreover, wc would like the stations to be flexible 
enough to cope with changing requirements on directivity, frequency 

- 8 - 



'J 



K sJS e » e * c » • without being overequipped and overstaffed.. EO 3.3(h)(2) 

PL 86-36/50 USC 3605 

4. The best way of illustrating the requirements placed on US' fa 
to discuss a few types of transmissions we have to intercept. About 
, the Russians started to employ 



transmission which they had never used before. This increased the 
number of types of Russian transmissions v)e must be capable of 
intercepting. The Russians also employ 



We can usually intercept the single qhannel 



jand others, 
transmissions 



using standard equipment. However, the requirements of 



dictated that more information on the transmission had to-be 



obtained. This required that something had to be added to the stand- 
ard equipment. As an example we consider two Russian stations, A 
and B operating full duplex and employing start-stop teletype. Such 
a situation may be considered as equivalent to two send positions each 
employing an enciphering device and a teletype. Except for the fre- 
quencies used, the positions A and B are essentially identical. 

What we would like to. obtain now is the time relationships in the 
messages passing between A and B . We definitely wish to pick up 
and record the time delays between the slops and restarts which 
occur during transmission. A may send to B for a length of time 
and then stop for one reason or another. During this pause, B might 
sjtop sending to A . Using standard start-stop equipment, we have no 
way of knowing when A or B is not sending. One requirement on 
intercept of this signal is that we record both sides of the duplex link 

- 9 - 

TOP SECRET EIDER 








TOP SEOKBffi 5 MDER 



EO 3.3(h)(2) 

PL 86-36/50 USC 3605 

simultaneously. If the recording is equally good on both sides of 
the communications channel, and if time relationships are known, 
then a side by side character analysis will ppint out where "busts" 
occur. When this problem first arose we had no means of using 
on-line page printers in the field to give us exact time relationships 
for both channels of communications. 

We now obtain time relationships by means of a tape recorder. 
lVhat we use are dual-track magnetic tape recorders. This equip- 
ment simultaneously records the activity on both links of the channel 
and makes analysis much simpler. 

5. A great deal of our efforts in this particular intercept problem 
is directed toward obtaining accurate copy. In some instances we 
employ the Central Processing System wherein the intercepted signal 
is analyzed and copied (usually from magnetic tape recordings) under 
controlled laboratory-like conditions. Originally this system was 

i 

devised to satisfy the side by side presentation requirement on the 
copy of duplex signal. We employ a similar technique on Russian 

Multiplex. This procedure is particularly useful where we 
are not able to set up demultiplexing ex^ipment in the field and keep 
it properly maintained. Instead we record the multiplex signal on mag- 
netic tape and then process it by means of the Central Prde<ssing 
System. 

We have found that Central Processing is not adequate to meet 
mass production requirements. We cannot, for example, afford to 




- 10 - 





PL 86-36/50 USC 3605 
EO 3.3 (h) (2) 

duplicate hour by hour in our central processing the time spent at 
stations in recording I trans mla a ions . We are, therefore, 

embarking on an onolfne printing program in the field, using model 28 
teletype printers to produce page print directly from the intercepted 

signals. For simplex and intercept, these 

» 

printers are modified in such a way that they will produce page prints 
which retain the time relationship between channels and within each 
channel. This program will in time reduce the amount of central 
processing required at this headquarter's. 

We are trying to produce standardization procedures td back up 
operations in the field. These procedures should avoid sonhe of the 
glaring errors that occur in the operation of field stations. We 
would .like- to find out if there is something wrong in a good percentage 
of ssta turns,, and if some stations are not carrying the load their equip* 
men4tis<capabie--of carrying. 

A\larg*"variety of equipment'is necessary to intercept any 
one type of .'transmission^ For instance, .we may be intercepting a 
double frequency -shift transmission one side of which is a 6-channel 
multiplex system, the othenside being a simple signal. To intercept 
this we require an antenna array to pick up the signal, a cable to lead 
the signal into a receiver, the receiver itself, a double frequency shift 
demodulator, demultiplexing equipment, printers and/or recorders 
and the various test and maintenance equipment. Not only does all 



- 11 - 





TOP SE C R ET* 6 E lDER 

this equipment have to be kept in good repair, but it must be 
properly operated as stated before. One of our biggest problems ,i$ 
to keep competent people on the job at intercept sites. In order to 
alleviate the shortage of trained operators, we are setting up the 
Civilian Intercept Operator program. We have been authorized 100 
civilian billets as a trial test. These are t'fSA billets which will be 
assigned to Army stations. We believe that by means of such a 
program we can develop and keep professional intercept operators. 

To take care of some of the complicated technical problems of 
intercept, we have set up the Technical Search Mission. Possibly 
in time we may be able to handle ultra -high frequency microwave 
intercept and find answers to some of the other plaguing problems. 

We are enjoying a little success in some of these problems but much 
remains to be done, R/D is considering many of these problems 
as well as the problems discussed in the preceding paragraphs. The 
next chapter will contain some technical details concerning the equip- 
ment discussed here and gives some specific recommendations on how 
this equipment might be improved. 






i ur or,* 



x 



isirrcTic 



B TRAFFIC COLLECTION ACTIVITY-II 
i. INTRODUCTION 

1. The Traffic Collection Activity of NSA is defined, for the 
purposes of this paper, to be the collection of raw traffic in the 
field and the subsequent forwarding of this traffic to concentrating 
centers both overseas and in the U.S. The problem includes the 
reduction of the traffic to a form suitable for Traffic Analysis 
and Cryptanalysis, said reduction .being effected at the intercept 
stations and/or the concentrating centers. The Traffic Collection 
Operation is described in Section II of this chapter. 

2. Section III of this Chapter attempts to present a quantitative 
picture of the effectiveness of the Traffic Collection Activity. This 
evaluation is performed first on a technical basis on those elements 
of the intercept system which are common to each of the three basic 
intercept positions now being manned by NSA. For example, antennas A 
transmission lines, and multicouplers, are evaluated first as they 
are generally common to Morse, Radio Printer, and Radio Telephone 
intercept positions. This evaluation is performed in the light of 
developments which are technically feasible within the present state 

of the art. It is followed by an operational evaluation of each of 
three basic intercept systems. The latter is essentially an 
evaluation of the Traffic Collection effort on the basis of operational 
factors and measures the administrative effectiveness of the organi- 
zation in terms of adequacy of personnel, of facilities [granting 




- 13 - 




technical adequacy of system components] and of coordinated planning 

in the collection of what is needed in a form" in which it can be U66d 

efficiently. In the broadest sense, this is a partial evaluation of the 

\ 

overall effectiveness of the management of the COMINT effort 
First, criteria of effectiveness and definitions of the scale of 
measurement will be given. Second, although the scale of measure- 
ment is admittedly coarse, the effectiveness of collection will be 
measured in a number of key .intercept categories, and attempts will 
be made roughly to assess the relative impact of the various effect- 
iveness gradations on the overall effectiveness of the COMINT 
collection effort. Last, an example will be given to serve as a rough 
measure of the loss to NSA in material which must be discarded, or 
only partially exploited, because of the inability to handle the mass 
of certain types of material in the form in which it is now collected. 
Throughout, when fruitful inferences may be drawn, particular 
problems will be examined in relation to functional categories [ICR, 
etc.] or other significant factors. 

3. The evaluation of the collection effort is performed with 
regard to the intercept of conventional communications signals 
below 30 me, leaving the evaluation of non-conventional signals and 
communications signals over 30 me to Chapter G. 

4. Section IV of this chapter contains comments and recommenda- 
tions. 



- 14 - 





II. GENEKAI DESCRIPTION OF THE TRAFFIC COLLEC TIO N 

P/ek aVion ~ 

1. The three types of intercept, which comprise almost all 
of the currenPtraffic collection effort of NSA and the supporting 
cryptologic agencies, with the approximate percentage of the total 
collection effort which they represent are as follows: Morse 
Intercept (69 percent), Radio 1 rinter Intercept (23 percent), and 
Radio Telephone Intercept (8 percent), a fractional percentage 

of the total traffic collection effort is devoted to " special signals" 

e.g. facsimile and microwave signals.. Some traffic is obtained 

by means which arc not 

within the cognizance of NSA and will not be discussed here. ^P 0 3 „ 3 i^,^ , 

° PL 86-36/50 USC 3605 

2. Before mentioning features of the collection process that 
may benefit from improved equipment or from mechanization of 
present manual processes, it is instructive to review the quantity 
and the nature of the traffic received. 

Traffic is obtained in many forms. The most common form 
is hard copy [one to -six copies of each item}. There is some 
manuscript single copy material and an increasing amount of magnetic 
tape recordings. Undulator tape and clean punched or chadless tele- 

. i 

type tape, microfjflm and photostats are also received in large 
quantities. Ther-te is also a small amount of high precision disc 
recordings and other miscellaneous media. 



- 15 - 





3. While accurate quantitative measurements are not 
obtainable, a few figures will illustrate the magnitude of 
collection activities. More than two 'and one quarter million 
morse messages are received each month as page prints. Over 
two million non-morse messages are received, not counting 
intercept that is not distinguishable as message units. More 
than two thousand magnetic tape recordings of -non-morse .signals 
and nine thousand pounds of perforated tape that cannot be 
divided easily into message units are received. From non-UtS. 
sources ■, come about three hundred thousand messages each 
month. These are on microfilm, photostats, perforated tapes 
and other media. 

\ 

4. The United States currently uses approximately 2115 
intercept positions [operator and associated equipment] of 
various types. They are located mainly in military. installations 
and in all parts of the world. Other sources are at best only- 
partially under United States control and, in the main, are 

not subject to technical improvement as a result of our efforts. 

5. The bulk of the raw material is received at NSA Head- 
quarters by courier. There are about 37 tons of such material 
delivered each month. In addition, nearly 30 million groups 

4 

a month are forwarded by teletype. They are largely duplication 
oi jnail shipment and represent priority material for which bulk 
shipment constitutes a back up. Upon receipt, raw material is 



16 - 



routed according to whether.it requires further processing 
to prepare page copy or 'merely sorting and~distribution to 
analytical sections. 

a. Generally speaking, magnetic tapes and punch tapes 
are processed at NSA Headquarters to produce page copy. Ii> 

* 

these operations, conventional communications equipment is 

used-. Sometimes preliminary scanning of intercept logs or of 
■ * / 
text printed on the tapes is performed to minimize the amount . 

of material to be listed. In all cases listing is at automatic'. 

or manual typewriter speeds [maximum 100 wpm]. 

b. Printed material is visually scanned and manually 
sorted and distributed by messenger to using organizations where 
additional classification and handling are frequently necessary 
prior to analytical processing. At least three copies of hard 
copy are normally required, one for exchange purpose, while 
others are used for Traffic Analysis and Cryptanalysis. 

HI. EVALUATION OF EFFECTIVENESS OF CURRENT OPERATIONS 
1. Technical Evaluation of Elements Comprising Intercept Systems 
a. Antennas 

The majority of antennas employed in the medium 
frequency and high frequency bands at permanent and semi -permanent 
stations are full rhombic s and non-resonant half-rhombic s. An 
atterrtjpt is made to lay the antenna fields out along semi-circular arcs 
norma!) to the direction of target coverage; for diversity reception, 



- 17 - 




2 or more rus»:Uc:» uf rhombics are installed. Each individual 
antunna has a mmiinal power gain of apprbximately 12 tp 16 db*aktd 
provides frequency coverage over about a two to one frequency 
range. Standard antenna kits are available to the services, for 
installation at intercept sites; thorough technical daita is available 
describing this operating characteristic* of these antennas. For 
example, a standard manual is available to all intercept stations 
■describing different hikch of rhombics, with details on the suit-' 
ability of each antenna in terms of target range, the db response 
as a function of frequency and from 4 to 22 me, and the ilb response 
for vertical incident wave angles from 0 to SO degrees. 

For low frequency and medium frequency ‘Coverage, , 
long wire (Beverage) antennas are installed, if physical conditions 



permit. 



For mobile operations, a standard military antenna 



kit is available which does little more than provide a mass of wire>' 
to string out, wherever physical conditions petmit-, to' try and ' 
capture as much energy as possible from the electromagnetic field. 

It is recognised, on purely technical grounds, that, 
antenna b superior to those antennas now being employed are avail- 
able. For example, by modifying the terminating resistor on a full 

• ■ 

rhombic, the backward response of the antenna can be modified to 
the extent of knocking out the response' in any specified backward 
direction. This could prove advantageous in reducing interference 



- 18 - 



in some cases, but this technique is not known to have been 
employed at field stations. Similarly, the possibility of 
employing resonant antennas, in particular the commercially 
employed Vee -antennas in stacked arrays, on certain fixed 
frequency targets, has not been exploited. 

A .rather thorough study of the effectiveness of the 

antennas employed in the COMINT collection effort has recently 

been completed by the NSA TMK, This study revealed that 

although the currently employed antenna systems may not be 

up to the level of modern developments, and recommended that 

.R/D undertake a critical evaluation of the problerrvby far the • 

major problem was in effectively utilizing the facilities which 

are available. It was found that NSA, in making intercept 

assignments, to a particular intercept station often did not use 

the available information on antenna facilities at that- station. 

It was also found that the technical groups in the services, charged 

with designing antenna fields in fulfillment of NSA assigned missions 

often did not know enough about the intended mission assignments to 

properly design the antenna field. In one case, involving mission 

assignments to the Navy, it was found-that the engineering personnel 

at the Bureau of Ships charged with the antenna design were not 

*TMB - The Technical Management Board is composed of represent- 
atives from tlie Office of Comptroller, P/P, COM, R/D, C/SEC, 
and PROD in NSA and from, the three Cryptologic agencies, ASA, 

NSC, and AFSS.- This Board has been charged with the mission of 
developing good management practices and techniques in the 
operational and technical areas under the direction of the DIRECTOR, 
NSA. 




- 19 - 



adequately cleared to enable a proper description of the problem 
to be presented. 

Steps are being takSn to improve this situation yet 
x^riich remains to be done. NSA (PROD) is making concerted 
effort to improve communications between the group assigning 
missions and the groups in -the field- attempting to fulfill these 
missions. In addition NSA (PROD) recently completed and 
distributed a publication " Antenna Handbook for Field Stations" - 
NSA (R/D) has prepared a technical description of a study to be- 
under taken by an outside group, under contract, to perform a 
critical evaluation of the adequacy of currently employed antenna 
fields in terms of optimum performance, minimum size, etc. 
b. Coupline Transformers 



The effectiveness of currently employed coupling 
transformers between antennas and transmission line was also 
studied recently by the NSA Technical Management Board.. The 
substance of this study was that existing coupling transformers 
did not adequately cover .the frequency spectrum. It was found 
that coupling transformers for operation with leverage antennas 
in the range 75 kc to 300 kc were satisfactory, but there were no 
coupling transformers for operating in the range 15 kc to 75 kc. 
Furthermore, it was found there were no transformers operating 
in the range 300 kc to 2 me; finally, it was determined that the 
range of existing high frequency transformer (4-20 me), used in 
profusion in the field, should be extended to cover the range 2-30 me. 



- 20 



The following steps are being taken to remedy this 
situation: (1) a coupling transformer design has been 'found which 
appears to cover the range 15 kc to 75k kc; this transformer is being 
evaluated in ft/D, (Z) joint service military characteristics for a . 
coupling transformer operating over the range 300 kc to 2 me are 
being prepared by the Intercept Technical-Comjnittee of RADAC*, 
and (3) the Bureau of Ships, which was found to be developing an 
improved cdupling transformer, has been asked to incorporate the 
joint cryptologic service agencies’ requirements over the range 
2 to 30 me. 

c. Transmission Lines 

. The effectiveness of currently employed transmission 
lines is another recent NSA Technical Management Board study. 

This study revealed that many stations were using open wire trans- 
mission lines with lengths ranging up to 3200 feet. Although the cost 
to install such a line is less than the cost of shielded co-axial cable, 
maintenance is a much more serious problem. It was reported in 
some cases that the open wire line was so long and in such disrepair - 
that the rhombic antenna at the terminating end of the line could be 
shorted and the received signal strength in the operations building 
undisturbed. 

Such situations as this were actually well known before 
the members qf the Technical Management Board undertook their 

*RADAC - The Research and Development Advisory Council advises 
the Director NSA on the programming, budgeting and implementing 
of R/D programs and the coordination of R/D requirements of the 
departments and agencies engaged in the National COMINT and COMSEC 
effort. This council is composed of the three Deputy Directors (R/D, 
PROD, and C/SEC), P/P, LOG, COMP, and S/ASST. 




21 




study. . NSA (PROD) had attempted to remedy this particular situation by 
letters to the services recommending the ueg of co-axial line. The 
services in turn had acknowledged the advantages of co-axial line and 
had begun to take corrective steps, in certain cases. They in turn, 
however, ran into time delays in their own supporting groups due to 
such factors as the requirement' to program for the funds to procure 
the co-axial. cable in the succeeding fiscal year. Once the material 

, \ 

was obtained and shipped to the intercept stations, additional delays 
were encountered in waiting for the engineering and construction 
groups to make the necessary installation. It is worth noting that 
such delays as this have been a major contributing factor to the 
fact that there has never been more than one case of a major antenna 
field change as a result of an NSA request. 

In March 1954, NSA (PROD) made another attempt to 
improve the situation by issuing an NSA Regulation establishing a set 
of minimum standards for all intercept stations. For example, -in. 
the case of transmission lines, over the range 2-30 me, shielded 
co-axial cable w'as made mandatory at all permanent and semi- 
permanent field stations. A maximum line attenuation of 6 db was 
permitted, thus limiting the length of the transmission line. 

Unfortunately there, has been little improvement as a 
result of this NSA Regulation. The reason for this lies chiefly in 
the fact that the services have considered these regulations to be in 

- 22 - 




4 



•the form of recommendations and advice only and therefore not 

binding upon them. The services do not consider these regulations 

* 

as authorative, basic guidance for the. planning of intercept installs-'- 
tions and for the determination of the adequacy of these installations, 
even though the regulations were issued as such. 

N5A (PROD) has recognized the situation and is now 
preparing a paper for DIRNSA on this subject. This paper is being 
prepared in 'the form of a letter to the services, to be issued by 
DIRNSA, in which he declares his intent to use hiB authority under 
NSCID No. 9 as the responsible agent for all U.S. COMINT resources. 
NSA (PROD) is planning to ask the director to use this authority (a) 
to specify the standard which must be met for acceptable COMINT 
intercept operation and (b) to evaluate intercept facilities to insure 
that standards are being adhered to. 

Should the suggestions offered to DIRNSA be acceptable, 

• it is believed that great strides will have been made toward solving 
a major administrative problem, 
d. Multicouplers 

An evaluation of the effectiveness^of radio frequency 
multicouplers has recently been completed by the Intercept Technical 
Committee of RADAC. It was determined that currently employed 
multicouplers fell considerably short of that which is technically 
available within the present state of the art. It was determined that 
the frequency coverage was inadequate, particularly below 

- 23 - 





approximately 3 me; the noise figures were oh the average of 15 db, 
while 8-10 db is considered 'easily feasible; .the generation of spuriou* 
responses due to intermodulation characteristics was found to be 
quite poor, it being estimated that these responses could generally 
be reduced by as much as 30 db. 

■ The Intercept Technical Committee of.RADAC is in the . 
process of completing a set of joint military characteristics describ- 
ing a multicoupler which is believed to reasonably well fulfill current 
and anticipated requirements. These military characteristics will 
serve as the basis for an R/D contract to develop this multicoupler. 
Past experience with the normal contract development-production 
schedule in NSA on an item as simple as thiB multicoupler indicates 
that 5 years will elapse from the time the military characteristics 
are agreed upon until the time production equipments will be in 
operation imthe field in quantity. However, it is possible to reduce 
this period by 30 percent, to 50 percent. To do so would require (a) 
streamlining the procedures associated with letting an R/D contract 
and (b) overlapping the development, service-test and production . 
phases. This would naturally entail a certain element of risk, but by 
sharpening the organization, this risk could be minimized, 
e . Receiving Equipment 

A general study of the adequacy of radio receivers being 
used in intercept operations has just been completed by the NSA 
Technical Marvagement Board. The substance of this study was that 
although certain VLF/LF and MF/HF receivers in use are obsolete 



- 24 - 



A JL/1 



and unsatisfactory for COMINT operations, there are other receivers 
covering the same frequency range which axe available to the services 
and are generally satisfactory. A few small problems with regard to 
these latter equipments, such as the VJL.F receiver bandwidths being 

i 

too narrow for optimum voice intelligibility and one of the h-f receivers 
not being as stable, by modern standards., as it could be were brought 
out. However, there are two new receivers about to. become available 
in quantity to the services; one receiver,' the R389» covers the range 
15 kc to 500 kc and the other receiver, the R390, covers the range 
500 kc to 30 me. These receivers are expected to rectify the problems 
noted by the Technical Management Board study group and bis satis- ^ 
factory for normal intercept operations. It should be noted that the • 
noise figures of these .receivers is expected to vary from about 3 to 8' 
db across the frequency spectrum, which by modern design and 
production techniques is considered to.be quite good. The dial 
stability, readability and overall receiver frequency stability of the 
receivers is truly outstanding. Although these receivers have yet to 
be employed extensively by the intercept services and it is always 
possible that unforeseen "bugs" , especially o i a maintenance nature 
may develop, high hopes are held for these equipments to satisfy the 
majority of the receiver intercept requirements over the range 15 kc 
to 30 me. 



- 25 - 



V>I\JL/ X JL/1 



As the result of a recent SIPB*study ( it was determined 
that increased emphasis should be placed bn the VLF portion of the 
spectrum in particular in the band from 3 to 15 kc. Although there . 
are no military receivers covering this range. -NSA (R/D) has 
developed an experimental model of such a receiver. A limited 

i 

number -of these equipments are being crash produced to fulfill 
these recently developed requirements. There are a number of 
technical deficiencies in this particular receiver and it is planned 
to contract for the development of an improved model during calender 



year 1955. 



The services use a variety of diversity receiving 'systems. 



some designs dating back to over 20 years ago. The latest equipment 
to become available in quantity is the AN/FRR-28, a dual space 
diversity receiving system which gives satisfactory performance. 
However, it is reported that there have been numerous component 
failures, and although the causes have been minor in nature, a 
maintenance problem has'resulted, nonetheless. A new dual diversity 
receiver is under development, the AN/FRR-23, wh^ch is yet to be 
technically and operationally evaluated. 

*SIPB - The Special Intercept Problems Board is composed of 
representatives from PROD, P/P, R/D in' NSA and from ASA, NSG, 
AFSS, and CIA. This Board is charged with the mission of studying 
special intercept problems and advising the Director of the conclusions 
and recommendations reached. Subsequent to his approval, thA Board 
is responsible for coordinating actions with NSA and other cogniagmt 
governmental agencies implementing the recommendations. 



f 



26 - 



NSA (R/D) has developed a dual diversity antenna 

\ . 

switch which switches between .antennas,, but utilizes only one 
receiver. A theoretical evaluation of this equipment' shows it to btf 
slightly inferior to a normal dual receiver diversity system. How- 
ever* due to the simplicity, of setting it in operation, it has been 
found in field research stations evaluations ‘to be generally equal to 
or slightly better than more complicated diversity systems. Eight 

i . ' * 

of these diversity switches are being fabricated for service tests 
'by the cryptologic service agencies. 

Recent investigations made in the field of diversity 
reception have shown that the existing diversity switching or 
combining units fail to take full advantage Of all that diversity 
reception offers. One design of a dual diversity system shows an 
advantage of 3 db over- the best of the more conventional systems. 
This 3 db advantage is not .a constant with signal levels* however* 
and in fact decreases for signal levels greater or less than an 
optimum value. Just what this new approach would mean in ► 

statistical terms in reducing garble rates of intercepted traffic is 
now the subject of an NSA R/D contract with a local concern. 






An evaluation of the adequacy of COMINT recording 
equipment has been the subject of an intensive study by the Intercept. 
Technical Committee of RADAC over the past year. This study has 
recently been completed and reveals that the services have used a 
wide variety of commercial and military recording equipments to 



fulfill voice and signal intercept functions. These units have not 
given satisfactory service, primarily due tp. their high maintenance 
requirements, fragility, and physical size. In addition, no singlfe 
unit was found to provide the requisite auxiliary functions needed 
in these services, and the variety of equipments in use has presented 
a standardization problem. On a recent trip by a member of the 

A*" 

Intercept Facilities Division in NSA (PROD), it' was found that at 
any one time almost 50 percent of the normally employed recording 
equipments were in the maintenance shops for repair. 

An NSA R/D contract is about to be let for the develop- 
ment of a rugged low maintenance magnetic tape recorder-reproducer 
requiring minimum panel space and suitable for recording and trans^ 
cribing voice signals in any language. The specifications for this 
equipment are based on a joint set of military characteristics 
prepared by NSA and the three cryptologic service agencies. Another 
Bet of joint military characteristics is under preparation calling for 
the development of a militarized magnetic tape recorder-reproducer 
capable of recording and reproducing facsimile and complex signal#* 
Based on the development and production schedules of the past, the 
program will require 4 to 5 years |t>r production models of both 
the Voice Recorder and the Signal Recorder to be in the field in 
quantity performing in fulfillment of the COMINT mission. 

Looking aha&d, it is apparent that some means for 
increasing the " packing factor" of information on tape would be of 



28 




major benefit to' the operation of the agency, not only from an 
economical viewpoint, but more important to reduce the bulk of 
material which must be handled. ' At the present time, NSA R/D 
is soliciting the interest of major commercial concerns interested in 
this problem. One concern has already put. forth a reasonable 
technical proposal for increasing the packing factor by an order, of 
magnitude. It must be emphasizedthat this work is a long range 
effort of a very basic, experimental nature. Based on past 
performance for research, development, and production, success 
would probably not be ‘felt significantly in field operations in less 
than 8 years". By following streamlined procedures, in particular, 
by significantly overlapping research, development and service 
testing phases, this time may be cut by one-quarter to one-half, 
g . Demultiplex Equipment 

(1) Frequency Division Equipment 

The vast majority of the frequency division multiplex 
signals being intercepted are known as " DFS" or "double frequency 
shift" signals. This type of signal is nothing more than a single 
carrier frequency, sharply shifted from one to' another of four 
possible discrete frequencies. Each of these four discrete frequencies 
corresponds to one of the four possible states which can exist between 
two single channel "mark-space" signals operating independently. 

For example, take two ordinary single channel teletype transmissions, 

- 29 - 






each comprised of sequence's of mar&s (M) ilid Spaces (S). If we let 
one teletype signal be represented 'by Kl-j or and the Other teletype 
signal represented by or S^, then at a'ny.’fnsthnt of tlrriet four 
possible states exist, i.e.M ? M, 

of these states is then represent' J by one of *€he four discrete 
carrier frequencies mentioned originally. 

There are two equipments utilized to demodulate this 
signal, one equipment operating from the intermediate-frequency 
fi-f) of a receiver, and the other Equipment operating from the 
audio (a-f) output of a receiver (the beat frequency oscillator of the 
receiver being on). There are many more audio equipments than 
i-f equipments, and audio equipments possess an audio diversity 
switching system', prior to. demodulation of the signal. Generally 
speaking, both equipments are satisfactory; however, very close 
scrutiny is being given the audio equipment, as it is being used to 
demodulate the Russian 
signal is one of the major technical problems which the Agency 
faces. NSA R/D has a contract for the evaluation of this equip- 
ment as a part of the whole Multiplex intercept system 

PL 86-36/50 USC 3605 

evaluation. eo 3.3(h)(2) 

Recently, requirements have arisen to intercept 
certain single-side band signals containing multitone transmissions. 

To date commercial and/or military equipments have been found which 
after relatively minor modifications, have proved satisfactory in 
handling cl..-. cases which have arisen. However, this situation could 
be: inr.provrc' since some of the equipments pressed into service were 



| Signal. This 



, Si s 2 * ^ S 2 , or Sj 1& 2 -. Ekch 



- 30 - 






TOP SlGR-BT £ BiBBR- 



PL 86-36/50 USC 3605 
EO 3.3(h) (2) 



> "border-line" in the sense that extremely high maintenance 
standards must- be met to keep quality of the intercepted traffic 
up to par. This technical problem is now being studied. 

(2). Time Division Equipment 

There are quite. a variety of time division demulti- 
plexing equipments in the field. There are "universal" demultiplexers, 

' both electronic and electromechanical, capable of handling from 2 to f) 
channels of time division multiplex traffic e.g. Model CXOF Universal 
Electronic Demultiplexer, and there are special purpose demultiplexers, 
both electronic and electromechanical, intended to specialize on a 
particular multiplex signal, e.g. Model AFSAV D-24 Two Channel 
Time Division Demultiplex Equipment. Generally speaking, the 
majority of these equipments have performed quite well. From time 
to time modifications to improve performance have been made. As 
an example, the "clock driving and synchronizing portion" of the 
Model CXOF Universal Electronic Demultiplexer is now being re- 
designed by NSA R/D to simplify the maintenance procedure. Recently, 

M ultiplex System, it was necessary 



with regard to the Russiai[ 



to provide a modification to the Model CXOF demultiplexer to enable 
it to synchronize with this new signal. An equipment capable of 

i 

taking .a shorter band length is also required. At the present time. 

Multiplex signal is 



a special equipment to ope rate on the | 
under development. This is necessary because of the general limita- 
tions of the CXOF equipment for the GTP intercept problem. The 



31 - 







main advantages of this new equipment over the Model CXOF will 
result from the fact that it is simpler .equipment, tailored for only, 
one signal, and hence the read out, a punched tape operated at high 
speeds, .will be much more efficiently achieved. All this adds up 
to a smaller device which should be easier to maintain. 

At a relatively low priority,' 'projects are being under* 
taken in NSA R/D to reduce the size and complexity of demultiplex 
equipment by the use of transistors, bi*stable magnetic elements, 
and specially developed tubes for counting purposes, 
h. Single Side Band 

The single side band intercept problem has come belated 
ly to NSA. It Is now the subject of a study by the Special Intercept 
Problems Board. It appears that the agency can fulfill its basic 
requirements with a recently developed militarized signal-side-bandl 
receiver. Model AN/FRR-41 to become available to the services in 
the near future. Until this militarized equipment actually does 
become available in the desired quantities, commercial equipments, 

electrically equivalent to the military equipment, can be put into 

* 

service . Additional requirements, over and above those which the 
fulfills, are expected to develop as a result of the 
Intercept Problems Board study. These requirements will 
.likely b$ filled by the development of an improved equipment under 
the auspices of NSA. 



- 32 - 




i . Mo r se Operato r Analysi s ( MO A) 

Morse Operator Analysis (MOA} is a process of 
identifying manual key (morse code) operators by the characteristics 
of their hand-set transmissions, viz by their "fist" The process 
of operator identification has been studied for many years, and 
although several different analysis systems afforded a limited degree 
of success in World War II, the use of MOA techniques during peace 
time was not justified until the recently developed AFSAV 031 Morse 
Operator Analysis equipment became available. -Heretofore, the 
task of measuring individual character elements on an ink tape 
recording and undertaking the process of averaging, computing, etc., 
was simply too laborious to interest those who would potentially 
benefit from this operation. 

In May 1951, development of the AFSAV D31 Morse 
Operator Analyzer equipment was initiated'in order to mechanize 
the particular analysis method which was widely employed at the 
end of World War II. This equipment photographically recorded the 
time distribution of dots, dashes and spaces on a Polaroid-Land 
Camera and similarly recorded the individual character formations 
on a 35mm. moving film. In the first model of (His equipment, the 
data from the Polaroid film recording was punched onto McBee 
Keysort Cards for mechanical selection of possible matches. Six 
of these equipments were fabricated, of which three were delivered 



- 33 



to the- cryptologic services f.o-r. sfe'rvice testingj-i t.wo \vere provided ■ 

. * . f «■ • " ■ 

■ ■ * ■ 

to CIA, and one wh s r etai ned.-in' NSA R/D foi : furthe.r e.yaluation. 

Installation of -the se r -.equip.ment*8; i'n-th e ! field, re suited ija. 

a renewed interest in Mor se. Ope r-at'&r; Analysis'.’by the. services. How- 

, . * H **. 1 ‘ • •'• “* . , ‘ . - 
• m ‘ J t * >i ." ", 

ever, uSeof the AFSAV D31 in' large scalfeTdentiflcationa of operators! 
under service conditions, indicated certain limitations inherent in the 

, * 4 . * **■ • r . •■ " V *• , 

' • • * , < , » , ■ • 

analysis system, Whenma-ny operators -had to be considered, the 
similarity between operators became increasingly .apparant. Invest- 
igations of 'other classification systems by’,NSA (R./D) revealed the 
same basic limitations.. It 1 ' was ipund, that a "best-fit" method of 
card comparison, substituted for- .the McBee Keysbrt,' increased the 
effectiveness of the' AFSAV D.il by a factor of a.bout seven under 
laboratory tests. As a result, an equipment, termed the AFSAV D69 
Card Comparator was developed to' operate in conjunction with the 
AFSAV D31 to enable. mechanization, of -the improved analysis procedure. 

At the present time, the AFSAV- DJi equipments are in a 
service test status and the fabrication of AFSAV D69 Card Comparators 
to go with this equipment is nearly completed. Concurrently, NSA 
(R/D) is in the process of contracting for the services -of a competent 
research group to study, evaluate, and develop' improved methods and 
equipment for identifying manual key operators. It is recbgnized that 
an investigation of improved MOA techniques is basically a problem 
in the statistics of small samples, and it is intended that the stildy of 



34 



tlVe collection of data and reduction of data for MOA analysis be .- 
directed toward the use of machine techniques. 

Whether any additional AFSAV D31/AFSAV Db9 MOA 
equipments will be built, will be determined on the result of the 
service tests now underway. The study contract will not be 
completed in less than a year and the development and evaluating 
of improved .MOA techniques in .the field wilt very likely require an 
additional 2 years-. If such work is carried out successfully, and 
Production equipments are required,- an additional 2 years should 
be -allowed for construction and distribution to the field; thus,' it 
will be at least 5 years before any significant COMINT utilization 
will likely be made of MOA techniques. As pointed out before, by 
streamlining procedures, this time could be reduced by one to two 
years.- 

j ■ Radio Finger Printing (RFP) 

Radio Finger Printing(RFP) is a process of identifying 

i 

transmitting equipment by the iuadvertant amplitude and frequency 
modulation characteristics usually present on any given transmitted 
carrier frequency. Basically, the operation consists of photograph- 
ically recording, on a moving strip film, two traces which describe 
the amplitude and frequency deviations from the norm of the intercept 
signal. 

From an analyst's standpoint, the problem of classification 












and cataloguing RFP data is difficult. Unfortunately. RFP analysis 
is more of an art than a science. The analysis operation is largely 
subjective and, based on the individual classifier's interpretation of thd 
evidence available to him. The currently used range of RFP charac* 

i 

• * 

tori stic s is large, and their potential identifying value, whether us^d 

i 

individually or in combination, varies within wide limits. Forth's 
reason, RFP identification reports must be considered as' graded 
statements of possibility or probability, the validities of which 
depends upon the number and nature of the characteristics involved 

and the amount of distortion (noise, multipath, interference, etc. ) 

EO 3.3 (h) (2) 

present in the individual records considered. pl 86-36/50 use 3605 

In spite of the subjectivenesB of the analysis procedure.* 
it has been possible to build up a large library of catalogued quantita- 
tive data; this catalogue was employed on the 



On this problem, RFP served in a relatively minor though 
valuable position as an aid in positively confirming Direction Finder 
and .Traffic Analysis reports; however, only six RFP equipments, 
out of a total of some 45 produced, were suitably located and avail- 
able on a world wide basic to attack this problem; hence the net * 
contribution from RFP was very small. 

The equipment in use today represents a modernized 



36 - 




version, circa 1950, of the original RFP equipment developed in 
1940. A study has recently beenxompleted on the efficiency of 

i 

operation of the equipment now in the fields This study was basest 
on a critical examination of 18Q monthly equipment failure reports 
from 14 different stations, coupled with interviews of approximately 
fifty people who had served at outlying stations -within the past 20 
months. The study indicated that the equipment was reasonably 
well designed and was capable of performing much better than 
failure reports seemed to indicate*. The equipments have been out 
of operation for maintenance a disproportinate percentage of the 
time, primarily due to poor training of the maintenance, men assigned. 
Cases are recorded where technicians have required thirty-ffve hours 
to ascertain that a cathode ray tube was not functioning properly; on 
other cases, as long as five hours have heen required to find that a 
rectifier tube was burned out. The nature ,of these failures has largely 
been such that redesign of the circuitry is not indicated. 

In' spite of the operationally developmental position of RFP, 
technical work has been undertaken in/NSA (R/D.) to improve the 
existing equipment. This work ha* taken two forms: (1) experimental 

■*'W. 

work on a system to employ r-ejrfsable magnetic tape in place of the 
one-time use of photographijr film or paper, and (2) development of 
a system to remove sompnof the subjectiveness from the analysis 
procedure in classifying RFP data. On this later point, an RFP 
correlator has bee/i developed which is fundamentally a simple digital 



37 




k. Direction Finding (P/F) 

’ * «- , i 

The majority of the direction finding operations occur in 
the high' frequency (2-30mc) range, where the bulk of the COMINT 
collection effort is applied. The equipments employed are pre- and . 

j> " «' 

early World War II designs which have begun to outlive their useful^ 
ness. They'are obsolete, . and maintenance is a problem. In addition, 
they, are not capable of coping with the kind of targets which may bd 
anticipated in a future war. This situation became clearly apparent 
in 1950 and possible courses of a.ction were studied. The Director, 

NSA,. delegated the problem of high frequency direction finder (HFPF) 

• , < 

research and development to the Navy, to be accomplished on behalf 
of all the cryptologic service agencies. 

The problem, as undertaken by the Navy has been stated 
as follows: "To meet anticipated operational requirements, it is. 
required that the HFDF networks be able to determine the location 
of a distant radio transmitting source within a few miles, when its 
emissions consist of short and extremely short signals. It must do 
so as rapidly as practical. As a first step, it must be able to cope - - 
with signals which last just a'few seconds. Ultimately, it must be' 
able to cope with signals which last only a fraction of a second." 

The /Navy analyzed this problem and concluded that a 
fully adequate Solution is difficult, expensive, and quite some time 
away. Accordingly; an interim solution was adopted, based on the 

- 39 - 



TOP SECRET EIDER 




use .of potentially Available equipments, and already developed tech* 
niques. The interim approach involves modification of present 
equipment, and procurement of new HFDF. network control and target 
acquization equipment. 

As a result of the Navy program, a new HFDF and net- 
work control equipment has been developed whi.ch incorporates all 
of the advances known to date. It is more sensitive) more accurate t 
and it is able to cope with signals of about 15 to 20 second duration. 

It is the best equipment which can be supplied now. Effective - 
operation of this new HFDF .to achieve its ultimate capabilities re- 
quires. provision of ancillary equipment. These HFDF stations will 
b.e linked with semi-automatic secure teletype circuits to attain 
rapid operation, in -response to the directions of the network control 
station. The most advanced type of conventional radio teletype 
equipment available- has been selected. 

The new type HFDF equipment and the associated fcontrol 
apparatus is now in production for the NavytAhd it fekpected to be 
delivered during the calendar ytear 1955. The £favy will receive 
sufficient quantities of this hew eqdiprrifeht to replace all of the exist- 
ing, outmoded HFDF equipment now Installed both within and without 
Jt'he Continental USA. By mid-1956, all of this new equipment should 
be installed and operating. In the meantime, the Navy R/D program - 




is continuing in the direction of increasing the sensitivity, accuracy 
and speed of operation of this 1 new net by developing improved search •' 
receivers and 'channel watching equipment. These improved equip- 
ments are expected to reach the Navy field stations by 1957. 

Unfortunately, the Army and Air Force cryptologic 
groups have. lagged considerably behind the Navy in improving their 
D/F nets. These two services are still using the outmoded HFDF 
equipment which the Navy is now replacing and they have not ordered 
replacements. They are thus about 15 years behind the Navy, although 
there appears to be no reason why they can not relatively quickly close 
the gap. 

Outside of the high frequency .band (2-30mc), comparatively, • 
little work has been done since the end of World War II. NSA (R/D) is 
currently making a survey of all reported military and commercial 
research and development efforts in the direction finder field through- 
out the entire radio frequency spectrum. This task is not being carried - 
on at a very high priority, although the part time services of a local 
consulting firm are under contract to accomplish the job. . At the 
present time , a report on the modern fftatg of direction finding is due 
in-NSA (R/D) by June 1955'. This report is intendeti^a serve as the 
basis on which decisions can be reached on the' research ahd^develop- 
ment tasks which should be undertaken in support of the COMINT - 
operation. As pointed out above, such research and development 



- 41 - 




pfqgrams normally lead to fruition at f^eld equipments many years 
after they commence; in the high frequency direction finding case, 
it is evident that great strides can be made by two of the three 
cryptologic groups based on the research and development work 
recently accomplished by the Navy, 

1, Autom atic Morse Translating Equipment 

It has long been recognized that automatic high speed 
morse, which is now taken on an undulator inked tape recorder and 
visually read, could be reduced to hard copy without a morse code . 
operator. Devices have been built in the past for recording the high 
speed transmissions on a magnetic tape recorder, then reproducing 
the signal at low speeds for either aural translation by an operator 
or machine translation by a relatively slow speed electric typewriter. 
Such devices were unacceptable in intercept operations not only 
because the equipments were large and cumbersome and required a 
slow speed reproduction of the traffic, but because an operator could 
more quickly and easily accomplish the job by visually scanning the 
undulator tape. 

In the past few years, however, a device has been 
built in NSA which permits on-line processing of high speed automatic 
morse transmission. It is possible to punch paper tape on-line at 
speeds as high as 350 to 400 words per minute (wpm) and convert 
to hard copy on electromatic typewriters. Although the electromatic 



- 42 - 




typewriter is limited to speeds of about lOOjwpm, the flow of traffic , 
to the typewriter often comes in spurts, averaging arouhd 100 wpm • 
or less. Four of these new equipments haVe recently been completed 1 
and are about to be employed in service tests by the 'cryptologic 
services... It is anticipated that these equipments will be used primarily . 
on those high speed automatic morse circuits where the percentage 

■ ' i* 

of legitimate traffic is high; on those circuits .where most of the traffic 
is "trash" which can be quickly spotted by an operator scanning an 
inked tape recording, the manual method is expected to predominate. ■ 
The extent to which the automatic morse translator can mechanize - 
this intercept operation is one of the basic reasons for the service 
test of this equipment. 

A study is being made in R/D of the applicability of the 
automatic morse translator to hand sent morse transmissions. Al- 
though the automatic equipment is capable of following average changes 
in speed of an automatic morse ..transmission, it is not adept at follow- 
ing a poorly sent hand-keyed transmission. This study is devoted to 
determining whether "classes" of hand^sent transmissions possibly 
cannot be handled by different settings of ti\e machine under close 
operator supervision. It has been argued that even if one morse 
intercept operator were required to constantly supervise 2 or more 
machines, this would proportionately cut down on the number of re- 
quired morse intercept operators. The training of morse code 



43 - 





• • I 

intercept operators is a major COMINT problem, particularly tq '£he 

i , , 

Army Security Agency this could be of material benefit. Prospects 
fp'r accomplishing much in R/D-in the hear future along the line of a 
simple, machine for in the field translation of crudely sent hand-keyed . 
morse' transmissions are 'quite low. 



m. 



Positions 



The intercept of 



signals presents the most 



difficult of the traffic collection problems. Fundamentally, the 
reason is that the cryptanalyst must have the higheBt quality traffic 
with which to work. Although there are a number of distinctive 

type signals, ranging from single channel synchronous - 

multiplex, it is primarily with regard 



teletype to the complex) 
to the 



multiplex signal that the greatest intercept problem has 
existed. The philosophy behind the intercept of this signal has been 
to make a recording in the field as close to the front-end of the 
receiving system as possible, thus demodulating the signal the least 
amount possible before recording. The record so made is then 
shipped to a central processing installation at NSA Headquarters for 
full demodulation and print-out of the hard copy; This procedure has . 



been adopted because it is believed that the demodulating equipment 



will be under better control in a central processing installation than 
at a field station; furthermore, the cryptanalyst has available for his 
close inspection, if desired, the incompletely demodulated signal. It. 



EO 3.3(h)( 
PL 86-36/r 



- 44 - 








has been argued that if interference is present, this procedure may 
enable the cryptanalyst and the central processing team to work to* 
gether in a much closer manner than would be feasible at a field 
station. Also central processing is the best interim procedure 
until demux equipment suitable for field use is developed. It will 
also be necessary to maintain a central processing facility to cope 
with future requirements. 

The result of this philosophy has posed a very difficult 
technical problem to R/D, for the recording/reproducing operation 
on the partially undemodulated signal must now introduce less 
distortion than full demodulation in the field would produce. After 
considerable experience with this 
that control processing on 
provided maintenance standards c 
raised considerably beyond what would be normally required on a 
more conventional system. The standards are so high, in fact, 
that it has been proposed that special Multiplex Maintenance 

teams be assigned overseas to provide maintenance on a routine 
basis. This proposal is now under study in the Agency. It is 
believed that the present system, when properly maintained and operated, 
is capable of producing traffic with garble rates of less than 1 percent 
on good signals. 

NSA (R/D) has developed and is continuing work on a 



intercept problem, it now appears 



J multiplex traffic is feasible 
n the equipment in the field are 



EO 3.3(h)(2) 
PL 86-36/50 



- 45 - 






TOP SE€ f 




EO 3.3(h)(2) 

PL 86-36/50 USC 3605 



large number of operating aids in connection with this problem. 
These include special tuning indicators to aid the operator in the? 
field in tuning in the intercepted .signal and holding it in tune. A 
garble rate indicator has been developed which measures the quality 
of the synchronizing channel in the multiplex signal in order to gaug 0 

traffic. A page copy print-out of the 



the quality of the 



traffic is desired by the cryptanalyst on a rather elaborate 
format, and a device to produce the material is under development 
and about to be delivered to the Central Processing group. A 
contractor is performing a thorough technical evaluation on the 
present system and proposing improvements. 



! 

There are a large number of miscellaneous items 
being worked on in R/D to improve the sensitivity, stability, and 
efficiency of this operation. However, operating under thb present 
philosophy of central processing, it is believed that it will be at 
least 5 years before the extremely high standards for field maintenance 
can be lowered by the introduction of a superior system to the field. 

The philosophy of central processing itself, on the scale now employed 
and envisaged, deserves close re-examination, 
n. Intercept Sites 

The selection of intercept sites is a difficult problem in 
which logistic/administrative factors must be considered in addition 
to the basic technical considerations. Needless to say, the selection 




46 - 







EO 3.3(h)(2) 

PL 86-36/50 USC 36' 

■ . r 

of any given site usually represents a compromise between many'. 

opposing factors; once a site is selected, the assignment of missions 

' * ■> 

also often represent a compromise between tKat which is technically 
desired and that which is administratively feasible. For example, 
the assignment of a complex intercept mission, such as against the 
Russian Multiplex signal, may be made to a station poorly 

located in. terms of the target signal, yet well staffed with a relatively 
strong operational group and possessing the necessary physical space 
to accept a large and complex intercept equipment. 

The appropriate elements in NSA (PROD) keep a running 
account on the times that intercept of a given signal is obtained at a 
given intercept site. This account is graphically portrayed by plottings ,, . 
the day of the month on the abscissa- of a chart and the hours of the 
day on the ordinate. The period of intercept then shows as a vertical 
bar, broken if the intercept was interrupted, for each day of the 
month. Compiling a large mass of these data provides the mission 
assigners with a considerable appreciation for the capability of 
intercepting given target areas from given intercept sites over a period . 
of time. 

It is very difficult to assess quantitatively the effectiveness 
of thd present method of site selection and mission assignment. One 
receives the impression that those people engaged in this operation - 







administrative factors in making mission assignments. It is onl)\in 
isolated cases that the operation obviously breaks down; then one. is 
led to suspect that the. system could be improved. A recent example 

Multiplex Mission 



is afforded by the assignment of a Russian 



to an intercept station 90 degrees off the'Veam of the transmitted 
signal; in another similar, case, the intercept station was 180 degrees' 
off the beam. In some cases, such a poor technical assignment may,. 

be warranted on administrative grounds, and technically acceptable . 

• * *\ 

provided the intercepted copy is still usable. However, when dealing 
With special cases,, such as I 



traffic * where the quality of 



traffic must be very high, then the evidence points to possibly improv 
ing the system. 

2. a. The operational evaluation definitions follows: 

Excellent • Substantially garble free traffic, the kind 
analysts need to work most effectively, 
against new crypto, call sign, address 
systems and so on. 

Good - Fully exploitable against known systems, and. 
permitting analysts to work at reduced 
effectiveness against new systems. 

Fair • Can be used if system is completely exploitable 
. but is useless in attacking new systems. 





PL 86-36/50 USC 
EO 3.3(h)(2) 





6 







Poor - Generally not usable. PL 86-36/50 USC 3605 

EO 3.3(h)(2) 

Traffic will be called: 

" Nearly all" excellent, good to excellent, etc. 

e ' / i 

if 90 percent or more falls in those categories, 
" Mostly" excellent, etc. if 80 percent to 90 



percent falls in those categori 



68 . 



Approximate figures will be given in other cases. 



the 



For Radioprinter, the criteribn isl 



specifically 



station. Intercept reaching NSA is nearly 

all excellent. Although this excellence is partly due to a rigid 

) 

field station screening program, the miBBihg serials in traffic reach- 
ing NSA do not indicate an excessive discard percentage, and undoubt- 
edly the screening helps catch troubles before they cause serious 
intercept loss. In any case, | | provides a 



excellence. However, the suitability of 



suitable criterion of 
as a criterion must 



be tempered by the following considerations. 



49 - 



N. 




1. las a very limited cover assignment 
and only hears approximately 6 RCA links. 

2. It is also a research station for T 'Department. 

3. Their manning standards are considerably higher 
than NSA standards. . 

4. It is a unique unit, the only one of its kind based 



on geographical considerations, 
tion, etc. 



> 



rganiza- 



EO 3.3(h)(2) 

PL 86-36/50 USC 



There is no criterion available for radiotelephone. 

What can be accomplished by the U.S. services is 
illustrated by the fact that about three stations, operated by two 
services are head and shoulders above the other U.S. service 
operated stations. 

The factor(8) for cited shortcomings will be cited thus: 
"Chiefly Responsible" - Correction of this factor 

would raise output quality 
more than halfway to 
nearly all excellent" 
"Largely Responsible" - Correction of both the 

Chiefly and the Largely 
(if any) responsible factors 
would certainly improve 
quality to " nearly all (90 
percent) good to excellent" . 



- 50 - 



r 






"Partly Responsible" - Correction of these and 

the above would generally 
■bring "nearly all (90 
percent) excellent" resultB. 
"Slightly Responsible" - Correction of these would 

generally serve to increase, 
the degree of excellence. 

Factors will be listed in decreasing order of importance, and evidence 

i 

will be cited for each, 
b . Morse 

Sixty-nine percefit of the currently manned U.S. intercept 

positions are assigned to Morse, both Matflial and Automatic. Most of f 

these positions are Manual, and most of the Manual positions are on 

Military Tactical* (Army , Navy, Air) assignments; in fact a single 

*For the purposes of this paper, the various communications 
intercepted for NSA have been divided into 6 functional categories; 

♦ i 

1. International Commercial Radio (ICR)' .Message traffic is 

handled by common carriers. 

. > 

t 2. National Commercial Radio (NCR) - Internal mes.sage traffic 

is carried by- common carriers or some state owned monopoly. 

3. Government Communications Services - (GCS) - Message 
traffic is handled by internal nets opeated by such government 
agencies as Border Guards, Secret Police and the like. 

4. j Military Tactical (MT) - "Low level" traffic is handled to 
i and from tactical military units; Army, Navy and Air Force 
"are included in this category. Exploitation of this traffic 

yields "order of Battle" information, and its intercept is 
generally considered a Close Support function. 

5/. Military Strategic (MS) - Potentially "High Level" traffic 
is. carried on circuits connecting higher headquarters. 

6. Support Communications (SC) - Broadcast and point-to-point 
communications, such as weather nets and broadcasts, and 
navigational aids and services are handled by various agencies, 
usually governmental. 




problem - 



accounting for nearly half the Manual Morse take, represents more 
than one quarter of the total intercept groupage entering NSA from 
all sources on all problems (excepting 



PL 86-36/50 U 
ED 3.3(h)(2) 



text). Most of the high speed Automatic -tyorse is on International 
Commercial radio (ICR) and|_ ' 



although great quantities of ICR are 

cipher, is 



] net$. 



intercepted, only a small percentage, mostly 
transcribed and sent to NSA: full coverage may be ordered on 
circuits. (NOTE: Low speed automatic morse, such as | 
are intercepted the same as manual morse.) 

(1) Manual Morse 

Under normal' conditions, and depending on service, 

i 

assignment and station, Manual jMorse intercept runs from nearly all 
good to excellent to as low as 70 percent go'od to excellent. The 1 



breaking into the new system to .one half the above figure, i.e. , if 
previous take had been 70 percent good to excellent, only 35 percent 

i 

was now usable; this drop was caused by operators copying the wrong 
v , cases as well as other factors arising from a changed situation. * How- - 
ever, appreciable recovery was noted in the first month after the change. 
When a situation, changes the percentage cut tends to be deeper- with the 



- 52 - 



TOP SECRET EIDER 









weaker stations, hence, in & crisis, the value of a station may.be 
substantially lower than the normal condition figures would seem to 
indicate. Factors involved in station and/6r service shortcomings 
include: 

(a) Chiefly Responsible - Operators 

Evidenced by: 1. Changes in efficiency 

when major personnel, 
rotations occur. 

2. Drop in efficiency in 
new situations in which 
technical factors remain 
unchanged. 

(b) Partly Responsible * Particular Problem Assigned 

Evidenced by: 1. Experience shows certain 

problems to be more 
difficult than others be- 
cause of poorer available 
sites' and other -factors. 

(c) Partly Responsible - Plant Facilities, intercept 

Assignments and other 
administrative factors. 
Evidenced by: 1. Such items as 12 mcs. 





to 3 and 4 mcs. problems; 
failure to lay out antenna 
fields according to 
problems; failure of NSA 
to give adequate informa- 
tion before station 
construction and similar 
factors. ' 

(d) Slightly Responsible - Technical inadequacy of 

available equipment and 
Techniques. 



Evidenced by: 



1. As described in Technical. 



Evaluation Section Above. 

It will be noted that the major factors susceptible of 
improvement are administrative in nature, and in regard to each of 
these the cognizant PROD element is now actively pursuing remedial 



measures. 



PL 86-36/50 USC 
EO 3.3(h)(2) 



(2) Automatic (High Speed) Morse 



Automatic Morse intercept is generally satisfac- 
tory. running' nearly all excellent on International Commercial Radio 
(ICR) and only a little poorer (largely because of signal quality) on 

| radio . Automatic Morse is generally transmitted at 
speeds as high as circuit conditions permit (up to 250 words per 
minute). Since high speed Automatic Morse generally appears on main 
line circuits, good operating practices are the rule and favor the 



54 





interceptor, who also profits from the fact that good copy can be' 
readily distinguished from bad, even when enciphered. The receiv« 
ing and recording equipment used is standard, and easily and quickly 
adjustable, and' the operation of a position is relatively simple td 
learn; hence, the stringent needfor skilled operators, so apparent 
in the Manual Morse problem, does not exist here. There are no 
special quality improvement measures required in this problem. 

However, manpower requirement may eventually he eased by the 
NSA (R/D) developed Morse translator (AFSAV D48) now undergoing 
service test. Otherwise, Automatic Morse intercept will naturally 

profit from the improved Plant Facilities which should follow current 

* 1 

PROD efforts; slight improvements may be expected to accrue, from 
such technical improvements as those described in the Technical 
Evaluation Section above. 

c . Radioprinter ipL 86-36/50 USC 3605 

EO 3.3(h)(2) 

Although only 23 percent (483) of the U.S. intercept 
positions are currently assigned to Radioprinters, clear text and 
enciphered on both single channel and multiplexes, approximately 
2,285,000 messages are intercepted per month. Most of this take 
is Russian and, sinceabout 80 percent of the circuit time intercepted 
is plain text, it will be seen tha 

represents NSA's largest single traffic source; however, the volume 
alone does not justify conclusions as to the relative value of this 




55 




EO 3.3(h)(2) 

PL 86-36/50 USC 



traffic compared with other traffic on a group by group basis. Most 
of this plain text, is I 



and 



it should be noted that more and more of these liqks are going to 

I single channel apd 

2 channel Baudot multiplex account for significant groupages, while 
other government communication services contribute some single 
channel; military and government communication service messages 
are generally enciphered, with more military 



T TT 

appearing. Both single channel and multiplexed rad^oprintejr aye pow 

‘i { 



copirpon op 



<1 / 



• ijir 7 



and are covered 



red the same as I I ^ptpma^ic Jwfo»pe| 



with aboqj: ||ie same degyee of success 

(l) 1 ' Russian Service Radioprinter 



Moat nf this traffir iaf 



Under normal conditions, only abdut two thirds of the take 
is good to excellent. This relatively poor showing stems largely from 
the fact that our operators are not equal to the greater demands made 



by the interception of military traffic as against 
in part, unfamiliarity with the language, sloppy transmissions 
(variable teleprinter speeds, frequency shifts, etc.), high percentage 



* There are many literal enciphering systems which are used to 
prepare messages for transmission by any means; the t.erm[ 



generally refers to a particular enciphering system used with auto- 
matic printing equipments. 









of enciphered traffic and frequently poor signals are contributing 

is even more demandifrg, bulf 



causes. The intercept of 



an evaluation qf the intercept belongs elsewhere in this paper. (See 
Chapter VII) Factors involved in these shortcomings include: 

(a) Chiefly responsible - Personnel - Operators and 

Maintenance; Men. 



Evidenced by: 



1. Changes in efficiency 

when major personnel 

PL 86-36/50 USC 3605 

rotations occur. EO 3.3(h)(2) 

2. Drop in efficiency in new 
situations in which 
changes in technical 
factors should not produce 
such striking effects - 
example: appearance of 

using unortho- 



dox shifts and printer speedsi 
(b) Largely Responsible - Plant Facilities and other 

administrative factors. 

Evidenced by. 1. Such items as lack of 

suitable diversity antennas; 
failure of NSA to give 
adequate information 
before station construction 
and similar factors. 



- 57 - 







(b^) Another factor largely reeponsible for poor traffic 
if the lack of a suitable variable frequency shift 
converter. 

(c) Slightly Responsible - technical Inadequacy of 

available equipment and 
techniques. 

Evidenced by: 1. As described iti Tech- 

nical Evaluation Section 
above. 

It will be noted that major factor* susceptible of 
improvement are administrative in nature , and in regard to each oi 
these the cognizant PROD element is now actively pursuing remedial 
measures. The NSA (PROD) on line Model 28 program will certainly 
be a definite and in the production of more accurate intercept. With 
a direct page copy, the operator willbe able to monitor his link more 
easily and will know when his traffic is garbled and can take the 




ntercept is 




PL 86-36/50 USC 
EO 3.3(h)(2) 



mostly good to excellent; an evaluation of the intercept of the 




ingle Channel and 



\feultipl< 



may 



be found in Chapter Vll, while the research and development aspects 



of the 



lultiplex are covered in the Technical Evaluation 



Section above;. Some of the plain text is on single channel radio* 
printers, but the great bulk of the mainline traffic is carried on 
Baudot time division multiplex systems, carrying as many as nine 
30 word per minute channels on a single multiplex. However, the 
Baudot system is obsolescent, and its rapid disappearance is 
foreseen. The' relatively good quality of this plain text intercept is 
due to the operator's ability to evaluate his resultB by looking at the 
output text, to the relatively high and consistent standards of Civil 

operation (as compared to the military) and similar factors. It 

* 

must also be borne in mind that higher garble rates are permissible 
in plain text traffic. Factors involved in existing shortcomings 
include: 

(a) Chiefly Responsible - Personnel - Operators 



Evidence by: 



Maintenance Men 
1. Previous evalua* 
tions of unu-sable 
traffic. 



(b) ' Largely Responsible - Plant Facilities and 

other Administrative 
faetprs 



- 59 - 










Evidenced by: 1 . Lack of suitable 

diversity antennas; 

t i 

failure of NSA to 
give adequate 
. information before 
station construction ' 
and similar factors. 

It will be noted that the major factors susceptible of 
improvement are administrative in nature, and in regard to each of 
these the cognisant PROD element is now actively pursuing remedial 
.measures. 

d . Radiot elepho ne 

About 8 percent of the currently manned U.S. intercept 
positions is assigned to radiotelephone, chiefly Military Tactical. 
Evaluated on an overall basis, this radiotelephone intercept is 
mostly good to excellent, and would be nearly all good to excellent 
if it were not for technical handicaps suffered by the operator-linguists*. 
Provided the operator properly adjusts his receiver and recorder, 
nearly all the intercept is good to excellent; unfortunately however, . 
that traffic which is garbled in transcription, in spite of having been 
properly received and recorded, is often garbled because of unuBual 
words or non-routine comments which would have special intelligence 
value and, therefore, the overall results - intelligence wise - fall . 





somewhat below what jyq^|d eeefri t$ bb indicated by 4 he "mostly 
goof to excellent" eva^fjipn. Factors involved in these shortcomings 
are: 

, (U Chieily Re'sponeible - Operators. 

Evidenced by: a. Equipment maladju stments 

and linguistic failures. 

(2) Largely Responsible - Inadequate Recorders 

Evidenced by: a. Lack of convenience items 

required for efficient 
transcription of voice 
intercept. 

(3) Partly Responsible - Particular problem assigned. 

Evidenced by: a. Experience shows certain 

problems to be more 
. difficult than other be- 
. cause of language, poorer 
available sites and other 
factors. 

(4) Partly Responsible - Plant Facilities and other 

administrative factors. 

Evidenced by: a. Such items as inadequate 

antennas and transmission 
lines: failure of NSA to 
give adequate information 
before station construction 
and similar factors. 




TOP SE( 



- 61 



(5) Slightly Responsible - Technical inadequacy of 

available equipment and tech- 



Evidenced by: 



niques, -excepting recorders, 
a. As described in Technical 



Evaluation Section above. 



It will be noted that, while two major factors are administrative in- 
nature, inadequate recording equipment is an important factor. Cog- 
nizant PROD elements are now actively pursuing measures to alleviate 

i> 

/ 

the administrative factors, while current programs to improve recorders 



are discussed in the Technical Evaluation Section above, 
e . Qualifying Statement 



EO 3.3(h)(2)' 

PL 86-36/50 USC 3605 



In assaying the overall U.S. intercept performance in 
terms of the above Operational Evaluation, two points muiSjt be kept in 



(1) The criteria used - as 




generally equal or better these 

standards, but so do various other intercept services (some from 

f ' ; 

nations with installations technically inferior to those of the U.S.) 
as evidenced by traffic obtained through special sources. Even allow- 
ing that special sources usually bring in traffic these other groups are 

- * l 

peculiarly located or adapted! to intercept, one must weight heavily 
the fact that four to five years - in one case, ten years - combined 




training ami experience is required before a. man may become an 
operate* in these intercept -services. 

(2) The evaluations given have referred entirely to 
the quality of the intercept in the form it is transcribed at the 

EO 3.3(h)(2) 

intercept position,' without regard to the ultimate suitability of - PL 86-36/50 USC 3605 
that fo.rm. Thus, in the vitally important ! [ problem, currently 
accounting for .more than a quarter of NSA'b total take (excluding 

lain text)* only 4$ 4# given Basic 

Processing an$t the remainder is ignored on a geographical area 
basis; a« the groupage rises, this figure will decline. . The reason 
is that, so long as present techniques are the v best available, this 
Agency cannot - and does not plan to try - to process all Manual 
Morse because the typewritten copy made by intercept operators 
is fundamentally not adapted to methods which permit full 
- exploitation with reasonable economy of personnel. 

IVi COMMENTS AND RECOMMENDATIONS 

1.. The analysis of our traffic collection operation indicates 
that much can be done toward improving the effort. The area in 
which must improvement can be made is considered to be chiefly 
administrative, i.e. (1) inadequate training of operator and main- 
tenance personnel by the cryptologic services, and (2) lack of . 
definitive authority to enforce standardization programs on equip* 
merit, plant layout, etc. The importance of the personnel jproblem 




63 . 






-has been well recognized in .the Agency and positive corrective 

■ actions are being considered! and undertaken.*. NSA (PROD) has 

■ recently sponsored 100 civilian intercept billets in the' Army 
Security Agency under a pilot program which is intended to develop' 

■ a corps of permanent, highly skilled personnel for field operations. 
The problem of lack of definitive authority to enforce standard! zation 

|| programs is also recognized. Efforts are being' made with. NSA 

_ (PROD) to build up a group which will establish minimum standards 

■ for acceptable COMINT, intercept operations and insure adherency 

■ to these standards by conducting evahiatipns of intercept facilities. 

While considerable improvement of the traffic collection- 
M activity could be achieved by proper administration of field 

facilities along the lines indicated, there is also much that could 
| be done by way Of impletwenting an NSA program to devise better, 

sirhf>ier and! durable equipment for field use. 

■ Research dnci development on advanced intercept 

■ t« cliftl^Ue a Will haturiliy aid in the Traffic Collection operation. 

Ifhi OOritfacted ies earc B-de velopm ent -proddfetion schedule, as it 

I ffe tdfrintly being foRov/ed, requires approximateiy 5 years for 

full realization in the ii'itd. This period Of time is considered to be 

I 

■ too idng, but there is miich that could be dbne to cut this by 30 

m pe#fc6nt to 50 pbrcenf by streamlining current procedures. Research, 

* #eVfc&>£ment and production, when undertaken locally within NSA, is 

| - 64 - 

* TOP SECRET EIDER . ' 

^ : 



realized in the field in a fraction of the time which the contract 
program requires, as. is to be expected. However, there is roofrfr. 
//for improving this operation as well, particulary by speeding up 



the process for component procurement. 

It is to be noted-that the area for -which the most significant 
improvement in performance may be expdcted from R/D is less in 
connection Nvith the pure intercept of traffic itself than it is with thfe 
reduction of this traffic to a form more suitable for traffic analysis 
and cryptanalysis. This point is elaborated upon later in this report. 

3. It is believed that a closer tie between NSA (R/D) and NSA 
(PROD) would aid in establishing an R/D program which would be 
more closely tailored to the current and anticipated needs of the 
Agency. In the past, this connection has been attempted primarily 
by bringing NSA (PROD) personnel into NSA (R/D) on various 
committees and panels engaged in planning operations. It is believed 
that an advantage would be gained by having some of the senior NSA 
(R/D) personnel engaged in planning R/D operations, spend more 



time gaining a "first hand" 




65 




C TRAFFIC ANALYSIS 



I. I NTR ODUCTION 

Traffic analysis is defined as the stiujy of radio communication 

1 1 J > 

by all moans short of cryptanalysis of message text (either decipher* 

> ' ■ 1 t ■ i 

ing or decoding) so ns to produce unique intelligence, to aaaiBt 
cryptanalysis, to direct intercept, and to influence our own communi- 
cation security practices. However, the intelligence derived from 
message texts can have such a strong influence on the interpretation 
of T/A data that the functions of T/A and C/A are not entirely 
divorced in NSA. Thus the office charged with T/A responsibility 
is also charged with exploiting all easily readable cryptographic 
systems, and is designated the Office of Exploitation. For this 
reason we shall discuss T/A from the point of view of the Office of 



Exploitation rather than per se. 

II. DESCRIPT ION OF T/A DATA 

The principal data contributing to the end product of traffic 
analysis are contents of Bona Fide Messages, practice traffic, call 
signs! message headings, message routing, and transmitter identi- ■ 
fication and location. All these items arc interrelated, each con- 



tributing to the other as well as to the end product. We shall attempt 
here to indicate briefly the manner in which they contribute intelligence: 



- 66 



1. Cail Signs . Call Sigps indicate .lines of communication', which’ ' 
in turn indicate organizational structure. In general the more coriaplicat*. 
ed a call sign system is, the more .productive it is of intelligence once 

it is broken. The complicated system mu6t be more highly integrated 
in order to be intelligible. This greater unity usually reflects more 
completely the organizational structure ol the activity employing the 
.system. 

2. Message Heading. The format of the message heading tends to 
identify the country and service sending the message. In some cases 
it can even identify the originator and his geographical location. -In 
addition, the method of serializing messages can give indications as 
to routing, traffic volumes, etc. 

3. Operator Chatter . Chatter contributes miscellaneous bit's of ; 
information about equipment, operating schedules, personalities, 1 
local conditions, message routing, message content, encryption of 
call signs, etc. Chatter may also serve to link or associate encrypted 
messages, thereby yielding valuable clues to the cryptanalyst. 

4. Practice Traffic. . Since a given set of .practice messages is 
usually assigned to a small set of users, identification of a practice 

, message tends to identify the transmitting station. In the case of an 
unknown call sign system, practice traffic can be a valuable tool in . 
maintaining call sign continuity. A study of thethethods by which, 
practice traffic is generated frequently gives clues as to the method of 



67 







encipherment of bona fide messages. Practice traffic recognition is 
also very essential in order that Practice Messages may be culled 
out from bona fide traffic when other indications are either unknown or 
missing. 

5. Bona Fide Messages , (plain text and decryptions) These 
provide direct intelligence on any and all Subjects in' a rather obvious 
manner. 

III. DESCRIPTION OF T/A PROCESSES 

1. Analysis of foreign communications actually begins at the 

i 

point of intercept. The Morse intercept operator or the R/T tran- 
scriber produces in the form of page copy has best interpretation 
of what he hears on the air. In addition he includes certain paren- 
thetic notes on the hard copy which show such information .as 
frequency on which the transmissioh was heard, readability, time, 
case number, and any other comments which he feels may be of 
assistance in later analysis. In the case of other types of trahs- 

J 

missions, the intercept operator cannot contribute these latter com- 
ments, and due to lack of knowledge of the language, can seldom make 
any statements as to readability. (This is a serious problem as ou* 
radioprinter intercept is notoriously poor. It is believed that in 
many cases improper tuning is responsible for this and that a 
greater familiarity with the language would provide the operator with 
criteria by which better copy could be produced. ) : 



68 



2. In the cases for which page copy is produced at the intercept 
station (mahtial morse and some R/T), an elementary semi-procftis- 
ing of the traffic takes place at the intercept station. The extent of 
this semi-processing depends upon the local "take" and upon the 
number and calibre of available personnel. Except in the case of 
Naval traffic this semi-processing consists primarily of extraction 
and Borting of significant portions of the transmissions. The result 
of this semi-processing is called a TECSUM and consists oif a digest 
of all meaningful information intercept by the operators. 

The TECSUMS are forwarded by electrical means Ito NSA .and 

i 

to the theatre processing headquarters where they form'a basis for ' 
COMINT reports which are supplied to theatre and other iimtereBted , 
consumers. In NSA the TECSUMS are combined and furtifor proc- 
essed in a more complete manner yielding less timely but Ignore 
comprehensive intelligence. In this respect considerable; pr ogress 
has. in some instances, been made toward mechanization, since 
the TECSUMS are received on perforated tape which lendg itself to 
immediate machine processing {subject only to the correction of 
transmission error). 

3. After the semi-proceSsing at the intercept site, the raw 
traffic is forwarded physically to NSA (Washington) for mqre 
complete processing. Prior, to extraction of intelligence, the 

, I 

traffic must be put into intelligible and analyzable form, 'this 

- 69 - 



I 




involves trains cription, identification, editing, sorting and logging,, 
the' traffic . 

4. Transcription . Since there are at present no machines for 

i 

sorting or analyzing raw traffic, it must all be transcribed in the 
form of page copy so that it can be scrutinized visually and pyoc> - 
eased manually. This is true of all form* of intercept except 
hand sent morse and low-speed automatic morse which are taken 
down originally in page copy. The processes involved are as 
follows : 

a. Radioprinter intercept may arrive in the .form of punched 

4 

tape,- undulator tape, magnetic tape, or occasionally page copy. In 

, * i 

i 

. , 

any event it is transcribed — manually, in the case of undulator 

tape — into page .copy. 

b. Radiotelephone intercept is recorded on magnetic tape 
and is transcribed manually onto page copy by skilled linguists. A 
large part of this is done at the intercept site of at soma field 
processing center. It would bf desirable to be able to scan radio* 
telephone intercept automatically to detect the presence of key wordt- 
To accomplish this an analysis of spoken language with respect to 
phoneme construction and representation will be necessary. 

c. All other transmissions (except some facsimile) are 
• recorded on discs or magnetic tape and forwarded to NSA for 
research. 




5. I den t ification. In most cases the transmissions are already 
identified by the intercept operator through a foreknowledge of call 
signs and frequency schedules, i.e. because the operator kne^uuwhat' 
he was seeking to intercept. ‘ Identification consists of assigning S 
"case number" to the transmission. A case number is a sequence of 
four letters and five digits. The four letters identify the transmission 
as to country, service, and type (morse, R./T, etc.). The five digits 
identify the net and individual link. About 20 percent of the traffic 
arriving at NSA is unidentified or incorrectly identified. In identifying 

r 

traffic, all the techniques of traffic analysis are brought to bear on' the 
problem, since the traffic is worthless unless the originator can be 
identified to some extent. On some circuits, e.g. many radioprinters, 
the problem of identification is paramount, since cqlls are seldom, if 
ever, used and. little intelligence is passed on the circuit. (These 
circuits are, however, a potential source of intelligence as they are 
maintained in a standby state to carry overloads from other circuits.) 
In the case of hostilities or a breakdown of landline facilities, these 
circuits are capable of handling a great deal of traffic. 

6. Editing and Borting . These are the most time-consuming 
and tedious operations in the agency. In some divisions of NSA-90 
as much as 85 percent of the personnel and time is devoted to these 
operations. In order for intelligence to be extracted from copy, it 
must be presented to the analyst in some logical order. The particular 






order will depend on. the type of intelligence to be extracted. In gen* 
eral the operations proceed more or lees ae follows: First, the 
traffic must be sorted by case number and ( arranged in' chronological 
order. At this point the chatter .can be analyzed, call signs logged, 
and messages decrypted or extracted for subsequent analysis. At 
the same time the intercept operator's parenthetic notes are taken 
into account and appropriate changes made. Also the traffic must be 
"deduped" . This involves searching through all the messages trans- 
mitted, and combining duplicate n^es sages, i. e. , comparing and re- 
solving discrepancies. The "deduping" is not confined to, an individual 
link. A search across all related links must also be made. This, in 
addition to giving a "best" copy of the message, gives information as 
to message routing, the importance of which we have previously noted. 

After the messages have been deduped, and classified as to prac* 
tice or bona fide, they must be classified according to cryptographic 
system and transcribed (perhaps in decrypted form). If the messages 
are easily decrypted, then the consequent intelligence must be logged 
in such a manner that it can be evaluated properly and later included 
in an intelligence report. Some of these messages are individually of 
no intelligence value. The intelligence to be derived would be of a 
statistical nature arising from the evaluation of a large number of 
such messages. An outstanding example of this is the Russian l I 
system in which several million messages per month are 

EO 3.3(h)(2) ' 

PL 86-36/50 USC 3605 

- 72 - 

» 

TOP SECRET EIDE R- 




TOF 



PL 86-36/50 USC 3605 
EO 3.3(h)(2) 



passed. An individual-message is merely 



However, the totality 6 f 



messages, when properly evaluated, gives a vivid picture of the 

V > l 

system (both organizational and geographical), 

i 

(concentrations etc.. 



Russian 



If the messages are not easily decrypted or are encrypted by 
an .unknown system, they are passed, together with identifications 

along to the cognizant cryptanalysts. There they undergo further 

'[ 

transcriptions and sorting in various (and frequently hot predetermined) 

r i 

forms. This is discussed in detail in another chapter. 

7. Analysis. ' References have already been made in the preceding- 
paragraphs to the actual processes of traffic analysis Although it is 

i 

believed that the bulk of what is how called analysis is in fact paper 
shuffling (i. e. getting the data into the pjroper order and form) which 
could be mechanized, there still remains the problem of evaluation, 
which must ultimately be done by a person. Phases of traffic analysis 
which cannot be profitably done by-machine are the following: 



a. Decision. The analyst mJst continually survey and resur- 
vey his raw data, in order to determine what intelligence .can be ex- 
tracted and which facets of the data contain this intelligence. This is 
.4 a very important aspect of both C/A and T/A . Old sources of intelli- 
gence are constantly disappearing and new sources crop' up. . The 

i 

analyst must be continually on the alert for new sources. He must 



- 73 - 



TOP SECRET EIDER 







' i " 




then decide how the intelligence la to be extracted , or in what form 
the data must be preaented in order to facilitate extraction. He*roust 
slab estimate the amount of work involved and decide whether or not 
the latent information la of sufficient, value to warrant the expenditure 
of that effort. 

b. Evaluation . The analyst muat'ianalyse the intelligence 
produced byth® above processes, decide whether or not it ia of signifi=> 
cance, draw conclusions (preferably probability statements) from it, 
and possibly decide what further processing is called for. Finally , he 
must compile the intelligence in as complete, yet concise, a report ao 
possible for delivery to the consumers. , 

8, Filing and Storage . In order to properly evaluate data, the 
analyst must have access to the past history of a situation. This ana 
tails storage and indexing of all significant data as it occurs. The data 
to be otored consists of raw traffic and information extracted from 
traffic or other collateral sources. The former io primarily a storage 
problem, as the need to consult eld raw traffic is relatively infrequent, 
and when called for, the identity and location of the traffic io usually 
known. Projects FREEZER and DEFROST or© expected to han&lo this 
problem adequately by microfilming ail traffic and providing a machine 
for quickly producing photeotatie eopieo of any selected portion. 

The problem of filing information io oomowhat different, An 
item of information, to be fully exploitable, muot be Sled under a 



o 74 



a 




I 



number of different categories, and in such a manner that is physical* 
ly easy to locate- -and read. Due to the bulk and variety of information, 
■sthis has become practically impossible with conventional methods of 
filing. Additional filing space is no longer available, so that only a , 
carefully selected portion of new information can be filed, and this 
at the expense of old but potentially valuable information which must 
be burned. 

Although the problem of space will be solved (at least tempo* 
rarily) by the move to Ft. Meade,, the paramount problem of access 
will still remain. Files are of little use unless they are,extensively 
cross-indexed or can be scanned easily and quickly. Cross-indexing 
is in general unsatisfactory with the type b of problems encountered 
here because of multiplied bulk and because it is impossible to predict' ’ 
all the indices by which it may be desired to enter the file in the future. 
At present many potentially productive avenues of research are con- .. 

. i 

stantly being blocked by the work factor involved in collecting the 

t 

data ff-om bulky and inadequately catalogued files. 

iv. Magnitude 

h Table A gives a breakdown of the estimated 350 million 

1[5 -Character)’ groups which must be pro^S’&e^i monthly by NSA-90 

/ 

during 1956. (The overall present figures are about^^ percent less.) 
/These figures represent dbfcut 80 percent of the total t r af f oc da S ed 
by NsA f although somewhat less than 80 percent of the total analytic * 
effort. 

I 

- 75 - 

TOP SECRET EIDER 




2. Table B shows the extent to which we are able to exploit 

‘l 

our present take of traffic. ' In this table "Basis Processing" means 
sorting, scanning;- and extracting elementary T/A information. . 

"Advanced Processing" means dec ryptiop of known systems and 
more detailed traffic analysis. It does not imply complete exploita- 
tion. It would be quite optimistic to assume that 25 percent of 
inherent Intelligence has been extracted even from that traffic which , 
has undergone "advanced processing" - 

3. After advanced processing there is still a great deal of intelli- 
gence which could be recovered by cros-e-reference, collation, and 
proper statistical and mathematical treatment of the results. These 
are not fully exploited for two reasons. First, all available personnel, 
are swallowed up in the task of basic processing, which must necessar- 
ily be done first and always. Secondly, although most of the advanced 

I 

analysis could be done by machine, the data to be analyzed must first 

be put into a form adaptable to machine treatment. This is impossible 

with our present (or any reasonable future) complement of key punch 

operators. PL 86-36/50 USC 3605 

EO 3.3(h)(2) } 

V. COMMENTS AND RECOMMENDATIONS 

1. From fifty to seventy five percent of the basic traffic processing 
now being done manually' on specific problems, such as Soviet |~ | 

could be done much more quickly and efficiently by 

machines. The biggest problem is that of data handlings However, a 



- 76 - 





TOF -S 






machine cannot handle data intelligently unless the data is in a form 
« ** 
which the machine can interpret. There already exist means for * 

mechanically changing coded data! (in the fprm of magnetic tape* 

punched tape, punched card, etc.) into page copy. But there is 

as yet little hope of developing a practical' method of changing 
' ' ■ - ‘ 
page copy-into coded form. Furthermore,, there is no likelihood 

that the manpower will ever be sufficient to accomplish this procesa 

manually to the extent that is desirable. Add to this the fact that . 

intercept is transcribed from two to five times during processing, 

and it becomes evident that the only solution is that the intercept be 

taken down originally in coded form. This is mechanically easy to 

accomplish, but it will require considerable research into the. require- 

' n 

ments of the analysts to determine what form to use, how to include 
parenthetic notes, how to edit it, etc. It will also require. the develop-, 
merit of some extremely flexible type of data editing equipment in 
order to take maximum advantage of the operators 1 parenthetic 
comments. 

2 >/. Another advantage ih taking down intercept in coded form will 
be realized in that it will then be adaptable to immediate super encipher* 
men) and forwarding by electrical means. Although it appears unlikely 
that we will ever have the facilities for forwarding all intercept 
electrically, there should always be means available for electrically 
forwarding any given portion on a priority basis, in case that portion 




should become productive of critical and perishable intelligence. 

3. There is also a need for a more adequate method of filing 
COMINT and collateral intelligence (as discussed under Filing and 
Storage). A system somewhat as follows seems to be indicated: 

a. A file containing punched cards' (or the magnetic equiva- 
lent of punched card). Each "card"' woul& contain an item of intelti- 

t 

gence and a code symbol indicating the format in which the intelligence 
is entered. For example it may contain, with respect to an enemy 
activity, the basic . station trinome, military unit number, location, 
subordination, types of transmission, type of operation in which - 
engaged, date, location (in the raw traffic storage files) of the source 
of this information, special remarks, etc. Other types of information 
cards might be case activity summaries, personality files, traffic 

i 

resumes, cargo information, etc.: 

b. A means for electrically scanning the file at high speed in 
search of any specified logical combination of the bits of data (for 
example, to search for all evidence of submarine activity in the Japan 
Sea between 1340 and 2400 on 12, 14, or 17 Apr^l 1931 or 26 Jan 1957)'. 

ft 

c. A means of reproducing the items selected either on a screen 
or in the form of page copy. 

d. A means for revising or erasing information already entered 
into the files, as well as a means for entering new information. The 
File should be capable of being consulted locally by the individual 




78 




seeking the information. Probably the tasks' of entering, revising and • 

erasing data should be left to specialised personnel. 

■ _ ' < 

The basic components for a device of this type already ,exist. 

The IBM 702 could probably handle. a year's volume.' of information. 
However, .a device with a much greater memory capacity and more 1 . 
specialized set of instructions would be niore economical and efficient;, 
4. Other than the equipments just discussed, there seems to be 
■ ’ little use for special purpose equipment in the office of exploitation. 

1 . I 

In general the problem is one of sorting, collating and. summariza- 
tion. After, these processes have been accomplished, there will also 
-. be problems of a mathematical nature and some problems of decryp- • ■ 
tion. However, each such problem by itself would be relatively small 
and of indefinite duration. It seems advisable to plan to treat these 

1 i ' , 

problems on general purpose computers until such time as their 

magnitude and duration ffidic^tp otherwise. At any rate, there would 

11 * . % . • 

be no point in building special puf pose equipment until we ave 

prepared to feed data to it. , 

1 , 

The " small" problems relsf^ed -tp a,b®ve are by no means un- 
important. They include such problems *;? sqmmarizatkm of results, 
DF. fixing, plotting locations of radar stations, and many. qth**s» Of 

late, much attention has been devoted by members of .90, 82, and. 34 

« * 

to. the mechanization of these problems on existing computers, and IBM 
equipment. This support should be continued, as the "small" mech- 
anizable problems are numerous, and new ones are constantly being 

1 i i 

created. ' 



- 79 - 




PL 86-36/50 USC 3605 
EO 3.3(h)(2) 



ESTIMATED GROUPAGE 

fiscal " MTIggT 



kigh Grade Low Grade 
Messages Messages 


Practice 

Messages 


Plain 

Text 


Chatter 


Total 


Groups to be 
Fwd. Electric- 
ally each 
month 


\ 

\ 

l,075,^o 


951,21*0 


1*,81*7,U*0 


2,096,620 


20,889,270 


29,958,-910 


5,228,600 


12,672,500 


l, 10 l*, 52 O 


206,000 


1,002,120 


2,101,590 


17,396,730 


2,800,000 


831,750 


2 , 063,520 


None 


1*82,01*0 


2,230,090 


5,657,1*00 


1,106,700 


7,717,21*0 


2,1*39,1*30 


5,1*1*0,050 


1,135,1*10 


2,697,890 


19,1*30,020 


U*,l*30,900 


306,360 


301,U1*0 


1,11*3,570 


955,1*70 


y,771,«W?- 


6,1*78,1*1*0 


1*, 61*1,150 


702,270 


1*7,050 


1*0,200 


None 


359,800 


1,030,520 


21*1,000 


735,270 


372,120 


5,268,680 


73,150 


39,011*,030 


1*5,1*63,250 


5,'625,600 


67,350 


7,1*53,1*00 


1*90,790 


5,621*, 820 


15,103,900 


29,01*9,260 


it, 002, 600 


712,1*20 


5l,07l*,120 


3,936,230 


None 


38,1*81*, 980 


9l*, 207 , 750 


22,867,200 


8,350,91*0 


121,11*0 


None 


81*,000 


5,571,010 


ll*,12 7,190 


2,357,880 


31,81*6,1*50 


11,295,290 


5,21*7,930 


2,070,1*00 


38,609,150 


89,069,290 


13,65U,800 



o 

cn 

Cd 

O 

Cd 

H 

0 



- 80 - 




Table B 



PERCENTAGE OF TRAFFIC PROCESSED 



Percentage of Traffic on 
which Basic Processing has 
been completed 



PL 86-36/50 USC 3605 
EO 3.3(h)(2) 



"Percentage of Traffic 
which has undergone 
Advanced Processing 



85* 








15 % 


85* 








30* 


100* 








85* 


-95*- 








60* 


100* 








hO % - 


85* 






- 


50 % 


85* 








50* 


UO* 








30* 


85* 








70* 



90 * 

95* 

90 % 

70 % 



30 % 

85 % 

15 % 

U2% 



Si. 

o 

C3 

Cl 

c5 

Cl 

* 



81 





D WEATHER 

EO 3.3(h)(2) 

I. INTRODUCTION . pl 86-36/50 USC 3605 

The Weather Division (NSA-95) and the weather field station* 
are primarily concerned with extracting Special weather intelligence 
from communications. Interest 

exists in European Satellites' weather Intelligence, but | | 

presently has responsibility for this area. 

Weather intelligence, to be of use to the consumer, must reach ' 
the consumer within six hours of the initial weather observation. 

The time involved in transmitting or delivering the intercepted 
weather traffic to NSA is far greater than six hours. Hence’, ifc 

i 

useful intelligence is to be extracted from weather traffic, the ■ 
traffic must be exploited in the field or the traffic must arrive at 
NSA within an hour of intercept. At present field units process 
and exploit the weather traffic wherever possible. 

The Weather Division at NSA concerns itself with the training 
of personnel for NSA field station duty, advises on the operation ' 
and functions of the field stations, and performs the cryptanalytic 
research and traffic analysis necessary to maintain and constantly 
improve intercept and analysis of weather traffic. Weather intell- . 
igehce reports are compiled in the Weather Division. 



- 82 



kded 



^v>ixvj_; x x-/xJ 



II. INTEREST IN WEATHER 
Our main interest in 



JEO 3.3(h)(2) 

PL 86-36/50 USC 3605 

weathef 



intelligence is due to the value of this weajther intelligence' in help* 



ing to predict or substantiate 



offensive 



action 



against their enemies. If a full scale offensive action were 



carried out by 



I weather conditions would 



to be 



have to be suitable for the scheduled activity. Also, if a full 

scale offensive were to be launched againBt / | 

weather conditions over the attack^area would have to be completely 

known- at least twenty four hours in advance. The development of 

» ! • \ 

nuclear weapons puts an. unusual value on all weather intelligence. 



Our secondary interest in thel 



weather 



stems from its value in predicting weather conditions in parts of 
the world other thanl I 



III. WEATHER TRAFFIC FLOW 




In the 



. weather observations 



are made at observation, posts and are transmitted as weather report# 
to collection stations which serve as assembly and retransmission 
points . 








The weather reports of the services do not flow in established 



patterns as do reports on the hydrofnet nets. There is a heavy 
exchange of weather -reports on an "as needed" basis. 

IV. INTERCEPT POINTS AND VOLUMES 



PL 86-36/50 USC 3605 
EO 3.3(h)(2) 




These systems are fully discussed 

in the chapter titled "Hand Systems" and hence will not be 
discussed here. The mechanization of the solution of these Bystems 
affords problems which differ little from some problems discussed 
in the chapter titled "Hand Systems." The amounts and type of 
mechanization required by the Weather Division vdll also be 
included there. 

VI. TRAFFIC ANALYSIS 



The traffic analysis functions of the Weather Division do not ' 



- 84 - 




TOR 



EBER: 



differ essentially from the functions performed in the Traffic Analysis 
Divisions. A discussion on the ^nech&nization of these functions'h^s 
been lylly discussed in the Traffic Analysis Chapter and will not be 
included here. 

VII. RECOMMENDATIONS 

1. Recommendations on the mechanization in support of perform* 
ing T/A and’C/A functions are included in the chapters on T/A and 

i 

i 

Hand Systems respectively. The specific requirements of the 

Weather Division should be carefully studied in subsequent phases 

- k .. . . PL 86-36/50 USC 3605 

of this project. EO 3 3(h)(2) 

2. If the exploitation of I Weather 



traffic is to be accomplished at the NSA, then the recommendations 
set down in the chapter on T/A on processing, traffic at field stations 

i 

and forwarding the traffic electrically to NSA also hold. In that 
speed is of prime importance in the exploitation of weather traffic, 
special requirements may have to be satisfied here. 

3. Efforts should be made to intercept weather traffic at the 
observation outpost level. Obtaining the traffic at this level will 
aid considerable in compromising the crypto-systems employed 
during later transmissions. 






E PLAIN LANGUAGE 



I. INTRODUCTION 

Analysis of plain language traffic accounts for a substantial 
share of the intelligence obtained on the economic and military status 
of the countries forming the communist bloc. This information is 
not as easily obtained from the plain language messages as one might 
suspect. In most cases considerable processing and analysis is re- 
quired to recover and recognize items of importance. In many cases 
relevant items are referred to by' number, drawing, or contract, and 



not by name. 



PL 86-36/50 USC 3605 
EO 3.3(h)(2) 



There are many types and sources of plain language traffic: 




j in that these fire representative of 

the type of processing and analysis required; moreover, they consti- 
tute an important source of information on the economic and military 



potential of 



COMMUNICATIONS 



communications are communications 



- 86 - 




passed on nonmilitary links, primarily those. of th 

The traffic contain? both official and private . 

respondence. The official part consists of communications between 

-all the traffic of this sort obtained by NS/f is through the efforts of 
our intercept stations. Almost all the transmissions utilize Radio- 
printer and Automatic Morse. There are some facsimile and voice 
transmissions. The total intercept averages 1,000,000 non-voice 
messages a month and approximately 1000 voice magnetic tape 

PL 86-36/50 USC 3605 

recordings. EO 3.3(h)(2) 

2. Non- Voice . The non-voice intercept is forwarded to NSA 
Washington where it is put through a preliminary scanning process 
which eliminates about 80 percent- of the traffic intercepted. The 
scanners, by process of noting key words, classify the remaining 
20 percent according to subject matter. The retained traffic is page 
printed, serialized, and microfilmed and then further studied with 
respect to criteria determined by curreift intelligence interests. 

The high priority material is further analyzed and the intelligence 
value extracted. Non-priority material is stored fox possible future 
use. 

3 . ' Voice- The voice tapes are forwarded unprocessed to the 
appropriate area in the Agency where they are audited by -lingfcfsts 








TOP 



PL 86-36/50 USC 
EO 3.3(h)(2) 



for intelligence content. Only selected portions are transcribed 
and sent to the analyst. . 

4. Intelligence . The foregoing processes of scanning, categor- 
izing and. subsequent analysis of voice and non-voice plain language 
intercept culminate ip a substantial amount of intelligence concerning 
the 



IV. INTERNATIONAL COMMERCIAL RADIO 

1. General . International Commercial Radio is a communications 
medium by which the commercial find governmental. organizations of 
the 



(and other nations as well) communicate with each 
other. There are some national' nets, controlled, by the 
services, which carry international commercial communications. 
Russian, Chinese Communist and Satellite traffic on the monitored 
ICR links received in NSA averages 100, 000 messages a month.- The 
national nets yield another 20,000 messages. a month. This represents 
only 5 percent of the ICR traffic interceded. Not all traffic on the 

' : V* 

ICR links is in plain language. From 50 thousand commercial 

code messages per month are also receiviSa. jhe code systems 
employed are mainly those which are c o mm ere ially available. Some 
of -the code systems are privately constructed'. It is estimated that 
almost all of these systems could be read if need be. However,, at 
present effort is restricted to reading only select commercial code 
messages. Few intercept stations are assigned to intercept ICR 



88 







— TOP 

traffic exclusively. Other stations intercept ICR plain language' 
but discard it when, they recognize it as such. 

2. Intercept Control. The intercept stations assigned to the 
intercept of ICR scan and select traffic according -to a predetermined 
scan guide. The selected traffic is forwarded to NSA where it is 
scanned according to the countries involved in the communication or 

a 

by the originator of the message and sorted accordingly. ( The traffic 
is then scanned for intelligence content. This scanning results in 
the retention of about half the traffic originally processed. 

3. Intelligence. All the | ~| and ICR messages which survive 
the preliminary elimination processes are studied by competent 
analysts. Several thousand messages a month are translated and 
published individually. The contents of many thousands more are 
-published in reports, tabulations, compilations, and summaries. AH 
messages of potential value are filed, several hundred thousand per 
month being retained. 

EO 3.3(h)(2) 

V. AREAS FOR MECHANIZATION PL 86-36/50 CSC 3605 

An area in which machines can give support is in the early sort- 
ing and selection stages where relatively sitaple but decisive operations 
are performed on vast quantities of traffic. SeYeral equipments which 
will assist in the mechanization of scanning and page printing operations 
and which will completely mechanize the page printing operation of 
I 1 radioprinter traffic are under development (these ate Project 





NELLY and Project BUDDY} 1 . The BUDDY device will scan chad- 
less tape and page print messages selected by message endings.'. 

The NELLY device will be an experimental model of a scanning 
device which will incorporate the function* of BUDDY aB well as 
select messages by category for <age printing. A modification of 
a Model 28 teletype machine will makef possible on-line processing 
of radio-printer traffic and the .automatic production of page print 
copy. Another current development is an electronic transcriber 
which will operate on-line in the recording of automatic Morse 
transmissions and produce hard copy. Since automatic Morse is. 
now recorded on undulator tape, the amount of tape that can be 
scanned is definitely limited. This electronic transcriber Should 
result in a considerable increase in the amount of auto/natic Morse 
traffic which can be processed. Automatic translation from undulator 
tape has proven a problem due to variability in,the inking of the tape. 
This is a problem on which more effort shoiild be placed. 

Scanning, categorizing, decoding', and printing of commercial 
code messages could be mechanize^ with slight variations on the 
NELLY approach. Other operations which might be performed 
mechanically include (1) Automatic language translation, (2) Automatic 
editing, mass data proposing of Ones sages , and automatic filing and 
file recovery, as discussed under Traffic Analysis. A potentially 
mechanizable pfe Id requiring additional analytic research is that of 



- 90 - 




phoneme analysis for the automatic detection of "hot" words in voice 
recordings together with improved equipment to perform this fuhdtioi). 






F MACHINE SYSTEMS 



i. INTRODUCTI ON 






K 



r 



1. Crypto -systems can be divided Intp two categories depending 
on how the encipherment is performed* by hand dr by machine. Hand 
systems are treated separately, and for purposes of this report 
machine systems are defined as those in which the key used is pro- 
duced as ehctpherment takes place; hie key is generated on the spot, 
lii some usages previously prepared key is combined with plain text ■ 
electrically or mechanically. These are not regarded as nrachine 
systems since they consist of mechanising a hand process. If it 
were determined that such key had been produced by means of a 
cipher machine, study of the key and the machine would of course 
be regarded as a machine problem. 

Cipher machines have many advantages particularly for middle 
and high echelon military use. They are rapid and usually provide 
printed copy; their use avoids many of the complicated problems of 
distribution raised by key pads and key tapes. Their speed o.f en- 
cipherment permits the handling of large volumes of traffic; tele- 
type systems can be operated at tape reader speed and so can handle 
message s’ several thousand characters long. Machines requiring 
no outside power source are very good for field use. These factors 
make cipher, machines particularly adaptable for military USe so 
that it is extremely likely that we will be working against cipher 
machines for. some time. 



- 92 - 






2. Two principal categories of cipher machinev'are those that 
use (1) rotors (wired rotors) or (2) pin wheels to produce key. A 
rotor is a wheel with two faces, called input and output faces, each 
with n contacts or studs and a set of n wires making electrical 
connections between the faces. The number of interconnecting 
wires is usually equal to the number of letters ih the alphabet of the 
language for which it is being used. Twenty-six is the most common 

number for western countries and thirty for Russia. With recent 

■ / 

developments such as re-entry (where a circuit may pass through 
the rotors more than once) this number can vary. The classical 
machine uses a series of rotors set between two plates, one of 
whose points are connected to the keyboard and the other to the 
printer. These are referred to as the input and output endplates* 
respectively. At a particular position or setting of the rotors a 
key is depressed, this excites a point of the endplate; the current 
goes through the rotors to the output endplate and thence to the 
printer. The resultant letter constitutes the encipherment of the 
letter on the depressed key at the indicated setting of the rotors. 

At this setting each letter on the keyboard will be associated- with 
a unique output letter. This association of all the letters makes up 
the enciphering alphabet at a particular position of the rotors. This 
alphabet persists as long as none of the rotors alters its position. 
However, if .one or more of the rotors move, a new enciphering 
alphabet is set up. The encipherment 'of each letter will 'then show 

- 93 - 



■ >1 a 1 1 B il eh I iila >■ iii I st iii n 




only an apparently random relation to itp previous encipherment if 
randomly wired rotors are employed. - 

A rotor machine then consists of a series of rotors set between 
a pair of endplates and a determinable means of rotating them (called 
the rule of motion) in such a way that a long series of apparently 
unrelated non-repeating enciphering alphabets is produced. Some 
machines have the property that enciphering alphabets are recip- 
rocal: (i, e. if A is enciphered by N then N will be enciphered 
by A) and no letter can be enciphered by itself. A rotor machine, 
called the ENIGMA, widely used by the German Armed Eorces 
during the last -war had this feature. The ENIGMA also had a set ' 
of jacks which permitted a daily rearrangement of the order in 
which the keyboard was connected to the endplate. The addition 
of these jacks provided more security than the addition of a rotor 
whose position must remain fixed for many encipherments. ' 

3. a. An example of the other type of cipher machine which 
uses pin wheels as opposed to rotors to produce key is the Hagelin 
model C-38 . A pin wheel is a circular disc with pins set in the 
perimeter that can take either of two positions. The basic principle 
of operation consists of sliding two alphabets, one in normal order 
and the other reversed, against each other in Bueh a way that suc- 
cessive juxtapositions of the alphabets depend on the internal structure, 
of the machine. Here each juxtaposition produces one of twenty-six' 
related alphabets since there are only twenty-six possible juxtapositions 
of twenty-six letter alphabets. Security is inherent in the highly 

- 94 - 



irregular sequence in which the various, juxtapositions are used. 

The sequence of juxtapositions or offsets is the key which is a function 
of the activity of' the pins and a set of lugs each of which provides for 
a single displacement of the alphabet. Again a particular setting Of 
the wheels is associated with a given displacement. In order to get 
a long series of such displacements the wheels are made to move. 

In the C-38 all the wheels move a single step between encipherments. 

To guarantee a long period before the series of offsets repeats the 

i 

wheels are made relatively prime. Thq C-38 has six wheels which range 
in length from 17 to 26 giving it a cycle length of about one hundred 
million. 

3. b. Another type of pin wheel cipher machine is one which 
generates key for the encipherment of the baudot code. The Baudot 
code is the binary code employed to represent the characters of the 
32 character alphabet of a teletype machine. The function of the 
pin wheels is to produce five binary streams, each stream may be 
represented as a series of dots and crosses or marks and spaces. 
Encipherment consists of adding these streams level by level to the 
plain text. The rule for addition is usually dot plus dot and cross 
plus cross sum to dot, and dot plus cross or cross plus dot sum 
to cross. Certain machines have a further encipherment at this 
• stage Which involves permuting the levels of this sum. Again it 
is cleqir that the wheels must be made to move since a particular 
letter of key will always be associated with a given setting of the 



95 





wheels. Also there mustjbe a wav of insuring ,a long period before 
fhsspquence of key letters start? to repeat. 

4. There are cipher machines which produce key through the 
use of telephone selectors.', pthers use commutators. There is a 
wide variety of methods of moving .the elements of the machine, 
but the machines mentioned above' sire the basic types. 

5. The cryptanalysis of these machines is extremely complex 
and mechanization of the methods of cryptanalysis requires a large- 
quantity of high speed electronic equipment. An outline of these 
methods will be given to show why sucfT equipment is necessary. 

We shall often speak of the "solution" of a cipher machine. This 
will have two meanings. The first meaning applies to the term 
"machine solution" whereby we shall' mean that enough information 
is known about the machine to allow us to simulate the machine's 

i 

deciphering (and hence enciphering) process. for example, the 
ENIGMA machine is solved when all rotors, their motion notches, 
their wirings, and the rule of motion are obtained. This informa* 
tion alone is not sufficient to ensure continuous reading of the 

device. Again,' the capture of a cipher machine and all its compon* 

* . - 1 

ents constitutes a solution of the machine. The second meaning 
applies to the term "daily solution" whereby -we shall mean that 
all the parameters of the device are known for the crypto~period. 
For example, the parameters of the ENIGMA machihe which change 
"daily" are the wiring of the reflector, and. stecker, the rotors- 




employed, their order and thfeir initial setting*. Thus to obtain &' 

"rpa chine solution" of the ENIGMA knowing the: nature of the 

, »* 

machine, we would have to recovef the number .of rotors that are 
employed and die wiring of ea^rh, Supposing there Ore eight avail- 
able rotors to be us e^ {three at a time, this 'would mean that we 
would have to try (?£!? wirings $for each rofor to recover the 
correct wiring. The number of trials necessary to recover- all 
rotors would approximate lfl^® • This number exceeds the number 
of atoms in the universe and obviously transcends the speed and 
capacity of electronic equipment which may become available in 

1 . i 

the foreseeable future. 

5. a. The cryptanalytic exploitation of the ENIGMA is a good 
example of the use of high speed machinery. The ENIGMA machine 
was used on almost all communication links of the German military 
.establishment. The wiring of the rotors was completely known 
because machines were captured; even so there remained many 
unknown elements in the encipherment of a message. First, the ' 
choice of rotors used and their order (In the Army an ordered sequehda 
of three was selected from a set of 5 . This can be done in 60 
ways.):, second, the setting of the rings which governed the motion 
of the Wheels (this can be done in 17,576 ways); third, the setting 
of the exterior jacks (150,736,274,937,250 possibilities); finally, 
the setting of. the rotors at the beginning of the encipherment (17,576 
possibilities ). This totals to approximately 1024 possibilities. 




having any particular way to make the correct guesses, exhaustive 
trials of all rotor orders, ring settings and initial settings would 
be required. This wouid amount to 10 billion man hours of work — 
clearly out of the question. However, it was possible to build a 
special machine, called a Bombe, consisting of sixteen analogues 
of the Enigma machine and a great deal of electronic sensing equip- 
ment which reduced the time to test a single assumption of wheel 
order, ring -setting, and initial setting to one millisecond. Further- 
more, it was possible to handle ring settings in rather large blocks. 
The effect was to reduce the time for a complete set of exhaustive ' 
trials of a matched plain and cipher to a few hours of Bombe -time. 

Of course, there wqre many possibilities for error; a garbled char- 
acter in the assumed plain text stereotype used as a crib (or a minor 
variation from bne day to the next) would invalidate the entire run. 



- 98 - 





5. c. When one message was read on a particular circuit on 
a certain day, then the rest of the messages- on the circuit that day 
were easier to read because the rotor-order; ring-setting, and 
jack-plugging would remain the Same for the! entire day. . 

5. d. More than 200 bombes were kept busy 24 hours a day 

- i 

breaking out traffic enciphered on the ENIGMA. The bombes gen- 
erally required 10 minutes per wheel order or about, 10 hdurs in the 
worst possible case. Various weaknesses of German usage frequently 
reduced this considerably. 

6. We see that while machine or daily solution by exhaustive 

» 

trial (or brute force) is not feasible with the highest speed equipment 
available today, solution by hand methods is also not feasible. What 

■ ’ * I 

is done is to reduce die number of trials to the point where solution 
can be achieved by high speed electronic devices. The bombe is an 
example of a machine designed specifically for the ENIGMA problem. ' 

With the advent of computers we have available a weapon for more 
general attack on cryptanalytic problems. By means of such devices 
it is possible to solve the ENIGMA statistically without the use of 
cribs. This, however, requires a fairly long message* but it' is an 
example of how more powerful equipment has made possible new 

PL 86-36/50 USC 360; 

methods of attack. EO 3.3(h)(2) 





EO 3.3(h)(2) 

PL 86 t 36/50 USC 3605 



derived from the reading o£ a depth — the encipherment of two or 
more different meeeages at thesiame set-up v of the machine* The 





This 



is an example of how modern equipment has made possible attacks 
considered out .of the question a short time ago. More detail of 
the solution! 1 machines Swill be given in the discussion O 



the solution! | machines will be given in the discussion Of 

Hagelin and Sturgeon problem’s. . 

7. b. The entering wedge to the solution and exploitation of 
cipher machines in most cases is a result of either the unauthorized 
acquisition of the rotor wirings and other details or the detection 
and breaking out of bust messages which result through machine 
failure or operation misuse. The first centering' wedge is self- 
explanatory and involves capture, theft, or defection. The- second 
covers all unintentional mis -use of the machine. 





II. 335 HAGS LIN PROBLEM 

1. The tfagetin machine, type C*38, is a cryptographic device, 
which involves reciprocal (in the sense that no encipher - decipher 
switch is needled) substitution and uses reversed standard alphabets 
slid against each- other according to' a long mechanically developed 
key. Slight variations exist but these variations do not effect this 
discussion. The initial offset, called slide, of the two alphabets 

is variable. The parameters involved in the manufacture of the 
key are (1) a set of 27 bars with two lugs on each bar, (2) a set 
of six pin wheels of lengths 26, 25, 23. 21, TO, 17 . Each' bar has 
eight possible resting places for the lugs on it — one for engagement 
by each wheel, and two neutral positions. The amount of "kick'* 

(distance and alphabets are slid for a given encipherment) is con- 
trolled by the activity (or inactivity) of the pins on the wheels, and 
the number of lugs set in the paths of the active -wheels. The 
presence of an active pin on a given wheel causes a kick of one for 

each bar having a lug ‘resting in the path- of 'that wheel. In the case 

EO 3 : 3 (h) (2)' 

where both lugs on one bar are resting in the p'hths of wheels,, 86-36/50 use 3605 
activity of either or both wheels will cause that ban to contribute 
.only one to the total kick. These wheels are said to be. "overlapped" 
by the number of bars they have in common. The wheel n^otion is 
regular — each wheel stepping one position before each encipherment. 

2. Properly used the Hagelin machine can be very secured 



- 103 - 

TOP SECRET EIDER 



*5. It can readily be seen that it is not feasible to apply all of 



the above outlined methods by hand. 




5. b. Several programs are available on digital computers to 
carry out both placement and statistical solution attacks, I ™ " 





a 7. Current Traffic and Readability 




■ VOLUME 




USER MSG /MO 


SUCCESS 


■ 250 


Good 


■ 300 


Fairly Good 


1 


PL 86-36/50 USC 3605 


60 


Good EO 3.3(h)(2) 


1 900 


Poor, can read depths 


5 

■ 


Poor, can read depths 


1 10 


None 


g 130 


None 


" 100 


Excellent 


■ 50 


Excellent 


V 

■ *See page 78 




■ 

- 115 - 




■ "TOP SECRET EIDER 







IDER 



USER 



VOLUME 

msg /mo success 



50 

200 



Fairly Good 
Excellent 



550 Partial (insufficient and 

EO 3.3(h)(2) poor intercept) 

PL 86-36/50 USC 3605 

1000 Partial (low priority) 



III. THE MODIFIED B-211 



1. Usage . This machine is a 



modification of the 1928 



commercial Hagelin Model B-211 




2. Descriptio n. The modified B-Zll is a wired-wheel cipher 
device. Input is via a standard typewriter keyboard; output may 
be a gummed tape or into an electric typewriter. The basfcc 
cryptographic elements of the machine are (excluding motor, 
print mechanism, gears, etc.) 

(1) Input and output fractionating devices (squares) 

(2) Four sets of pluggings (steckers) 

(3) Six wired cipher wheels (numbered I, II, III, IV, V, VI) 

(4) Four motion wheels (numbered VII, VIII, IX, X) 

Only the fractionating squares, the steckers, and the cipher wheelB 
are involved in' the actual encipherment of a letter, the function of the 
motion wheels being solely to impart a non -regular movement to the 
cipher wheels during encipherment. 

2. a. The fractionating devices can each be visualized as a 
5x5 square with the letters A- Z (excluding W ) written into the square 
in random order (the same order in each square). The function of the 
input square is to resolve a letter into two components (row and column)t 



- 117 - 




each of which is enciphered separately and then recombined in the 
output square to produce a cipher letter*. 

In encipherment (or decipherment) electrical pulses originating 
in the input fractionating square and ending in the output square actually 
pass through the pluggings and cipher wheel's. The cipher wheels and* 
steckers simply provide a path or circuit for the original pulses. 

Z. b. The cipher wheels are of two types: wheels I, II, III, 
and IV are rotors. Wheels V and VI are equivalent to a half rotor 
with a set of slip rings providing input and a rotor face for an output. 
Each rotor has 15 settings or positions. Wheel Bettings an* ’divided 
into three families of five each with family wired to family 

Resting against the faces of the rotors are endplates, ealch of 
which have five contacts which are spaced opposite every third con- 

„ i 

tact of the 15 rotor contacts. Thus a path through any of the five 
Input points of an endplate travels through the rotor, coming out at 
one of the five output points of the other endplate. Moving the wheel 
varies the paths. 

The half rotors have ten settings (in two groups, even and odd). 

On one face of the wheel are ten contacts, which ride against an end- 
plate with five contacts, whild on the other side of the wheel is a 
shaft with five slip rings. Each slip ring is wired to two of the points 
on the face, one in each family. Five brushes provide the input to the 
half rotor. 

The five brushes of each of the two half rotors are wired directly 
to the five rows and five columns of the input fractionating square 



- 118 - 



top ss ety^iMK 



respectively, so that encipherment proceeds from the fractionating 
square to the V and VI half rotors. 

2. c. The four variable steckers (plugging) in the machine per- 
mit further variation in circuitry. Two of the steckers connect thd 
output points of rotors V and VI with the iriput points of rotors I 
and IV . Herb we can have' V plugged to I (with VI plugged to IV ) or 
V plugged to IV (with VI plugged to I ) . The latter plugging in general, 
presents a more difficult problem of cryptanalysis. This plugging is 
referred to as "cross-plugging." 

The output points of rotor I are connected permanently to the 
input points of rotor II. The same is true of rotors IV and III . 

The output points of rotors II and III are plugged into rows and columns 
of the output fractionating square. A variation in "direction" of plug- 
ging is also possible here, so that II may be plugged into rows, with 
III plugged into columns, or vice versa. 

Each stecker has 120(5!) variations, there being five elements 
to plug. 

2. d. A block diagram of the rotor and stecker layout for the 
machine is given below. Here the fractionating squares are referred 
to as plain and cipher squares. Steckers are not shown but the heavy 
lines indicate where the plugging is located. 






- 119 - 

TPPP 



TT? TTTP^TI? TP) 



□ 0 



PLAIN 

SQUARE 



CIPHER 

SQUARE 



0 0 



Note that with any variation of plugging the order of encipherment 
of either plain component is 



Fractionated Plain 







For encipherment or decipherment by hand the wiring of the 

i 

rotors can be expressed as related alphabets, and the process of 
tracing a path through the wheels becomes one of successively 
applying alphabets to the plain components. 

3. e. The four motion pin wheels have 23, 21, 19, 17 settings 
respectively. Each wheel has a movable pin in its rim at each setting 
{axis of the pin is perpendicular to the face of the wheel) which may be 
set in an "active" or "inactive" position. Movement of the rotors is 
controlled by the action of the pins of the motion wheels. The 23 and 

- 120 - 

TOP SECRET EIDBftr 










21 pin wheels control movement of rotors V and II, both V and fl 
stepping if an active pin comes up in either or both of the pin wheels 
Wheels IV and VI are similarly controlled by the 19 and 17 pin 
wheels. These four rotors are called "fast" rotorq.they step about 
75% of the time. Rotors I and III are callbd "slow" rotors, since 
they step only 'when II and IV step from H to I respectively (about 
5% of the time). The combined cycle of the 23 and 21 pin wheels 
is 483 , after which rotors V and II undergo exactly the same 
sequence of motion. Similarly the cycle of the 19 and 17 wheels 
is 323 . 

3. Machine Meth ods. A number of machines and machine methods 
have been developed for application to this problem. These include: 

3. a. FROG , an electronic crib dragger which is an operational 
version of an earlier experimental electronic crib dragger (which was 
used operationally for over two years). FROG has been used opera- 
tionally since April, 1954 and occupies approximately 70 cu. ft. 

The purpose of this machine is to "drag" a 20 letter crib 
through a message in an attempt to find settings, steckers, and 
motion which convert the given plain into cipher. Only messages 
for which the plugging is from rotor VI to IV ("straight" plugging) 
are acceptable, and only those rotors involved in the encipherment 
of a single column component are considered (wheels VI-IV-III). 

The straight plugging requirement is the only limit to the 
generality of this machine. If a message is straight plugged (and 



- 121 - 




with the current indicator system about 40% of the traffic is straight 
plugged), and the crib is not garbled* then the machine will place it. 

Since FROG became operational all breaks into new cryptographic 
periods have been made with the machine. FROG is used about 100 
hours per month. 

3. b. Com p uter Program s are used for message placements 
when indicator groups are partially known. About 40 hours per month 
of data preparation time and 40 hours per month of computer time are 
used. 

3. c. Ana l ogs . There are three of these relay-type machines, 
which duplicate the cryptography of the B-211. Cipher is typed into 
the machine via an input keyboard; plain text is simultaneously typed 
out by an electric typewriter. 

Wiring of the cipher wheels, steckers (plugging), and motion 
wheel pin patterns are all contained qn plugboards, allowing complete 
flexibility of the machine. These machines are primarily used to 
decipher traffic, but their extreme flexibility makes them also very 
valuable in certain cryptanalytic methods. 

3. d. Handtes ters. These are simple devices, in effect, 
analogues of the B-211 without motion wheels. By manipulation of 
switches (steckers are plugged beforehand) a letter can be deciphered 
through any given cipher wheel settings. 

There are three of these devices. Their primary use is in 
the recovery of motion when cipher wheel starting points and steckers 
are known. 

- 122 - 




/ 




I 

I 



PL 86-36/50 USC 



EO 



3.3(h)(2) 



4. Standard B-211. The commercial B-211, which lacks the 







I 

I 




PL 86-36/50 USC 3605 
EO 3.3(h)(2) 







3. Machine Methods. 



A number of computer programs are avail* 

i — 






able to perform various processes for STURGEON, 





t^l_yv>!VJL/ J. MJjJ 



PL 86-36/50 USC 3605 
EO 3.3(h)(2) 




1, b. Purpl e. The Purple machine was originally built as an 
encipher -decipher device-. Depression of a key from a typewriter 
keyboard caused a jour rent to flow through a stecker, telephone 



— 1Z8 - 






PL 86-36/50 USC 3605 
EO 3.3(h)(2) 

Selectors, and back through the steeker where- finally a key from aq 
electromatic typewriter automatically printed the end product. 

Current frofn a set of six letters passed through a single six -input 
telephone selector while current from the other Bet of 20 letters 
passed through a bank of three 20-input selectors. All selectors 
had 25 levels. Various motion patterns were used but in any event 
the machine cycled at 15,625 letters. (Note that a monoalphabetic 
substitution on the plain-text would result without wheel motion. ) 

Motion patterns and steeker .were changed periodically. 

Some pages of early books of key were generated by typing one 
of five 500-long sequences for the link system or two 1250-long sequences 
for an early version of the circular system into a non-stepping Purple 
machine, thus essentially only applying a monoalphabetic substitution 
to the sequence. ) 




mill 







- 13Z - 



~T Qr SECRET EIDER 





These results are later sorted by IBM equipment into a more 
convenient order for hand examination. 

- 133 - 



TOP SECRET EIDER 



I 

I 





TV7I JI>v>iVjLy i JulL/I/lV PL 86-36/50 USC 36 

EO 3.3(h)(2) 



VI. ENIGM A 

The ENIGMA machine substantially as it was used by the German 
Army during the war has been resurrected by the East German 
Police. They pass about six hundred messages per month. Four 
stored bombes have been put back into service to cope with this 
problem. It is handled precisely as described in the introduction. 

The bom be is provided with a short stretch of matched plain and 
cipher. By making all assumptions of plugging, wheel order and 




TOP S8€^3^HDER 



settings these elements of the'key are recovered. This problem 
is also being used for experimental purposes to test new equip- 
frnent designed to work on rotor machines. 



VII. Rlfl 



VIII. ALBATROSS. 

Note: These sections are bound separately. 



PL 86-36/50 USC 3605 
EO 3.3(h)(2) 



IX. FUTURE MACHINES. 



1. Basic descriptions of the work done on a number of active 
cipher machine problems have been given. Some of these devices 
have been around for a long time and we must anticipate the day 
when they will be supplanted. Others are fairly recent and as yet 
unsolved. This is particularly true of those in which we have the 
greatest interest. Both of these facts are of tremendous impor- 
tance in any discussion of future equipment. In both cases we 
must expect more complicated devices designed expressly to over* 
come weaknesses that have become matters of quite common know- 



ledge. This means electronic equipment of greater flexibility and 



r 



extremely high speeds. 







- 136 - 





PL 86-36/50 USC 
EO 3.3(h)(2) 



It is clear that the solution of a cipher- machine involves the 
need for considerably more complicated high speed equipment. 

With each advance in the design of the device a much greater advance 
in the analytic equipment is required. For example, the outside 
motion control of the ENIGMA is a relatively minor change, but the 
redesigning of the bombe that is needed to cope with this is extremely 
difficult. It is therefore necessary to keep abreast of all developments 
in the computer field if we hope to cope with the cryptanalysis of cipher 
machines. 

X. COMMENTS AND RECOMMENDATIONS. 

' i 

Two dominant characteristics of cipher-machine problems are the 
small but definite number of parameters which have to be recovered 
to effect a solution and the tremendous number of trials necessary to 
recover these parameters. In the recovery of these parameters 
(wheel order, initial wheel setting, etc. ), analytic equipment must 
make use of available information such as cribs, busts, etc., and 
run through logical or statistical tests at very high speed. At the 
same time, the analytic equipment must be able to utilize an analyst 
designed decision process discriminating enough to limit probable 
answers to a manageable number while being sophisticated enough 

not to miss the right answer. The problem solution procedure has 

- 137 - 







two phases: entry and exploitation. Both phases require that equipr 
ments operate at the highest speeds currently attainable. The entry 
phase requires flexible general-purpose equipment that can be set 
up quickly to carry out any process that the analysts hit upon, i.e. , 
the machine must be easily programmed and readily available to the 
analyst. Too often suggested processes are not carried out because t>f 
the difficulty and time involved in programming the process and the 
non-availability of the appropriate equipment. The exploitation of 
any specific cipher machine usually is attempted and studied 1 on gen- 
eral-purpose equipment. After success has been attained, gristing 
special purpose machines are usually modified or new machines are 
designed to handle the problem whenever such machines are tnore 
efficient than the general purpose machine. In both phases computers 
are in most cases inadequate; they have the versatility but riot the 
speed. Analytic equipments that have the speed need further increases 
in versatility. 

In both these fields new and soiphisticated approaches have been 
proposed that present equipments are unable to handle. For the 
most part these approaches are characterized by requiring a com- 
bination of high-speed analytic equipment, large-volume data handling, 
and complex control and decision facilities. The importance of such 
attacks will increase as more extremely complex cryptographic systems 
come into widespread usage. 

The types of equipment required to best perform the mechanization 
of cryptanaly tic procedures are listed as follows. 



-138 - 




yAP — Cl? p 

1 Ur ijliURETI mUEK 

1* General computing equipment of substantially higher speeds 
than presently available (Atlas !I t tBM-701, etc. )• 

2. Data processing equipment of larger capacity and higher 
speeds than presently available (IBM-702). 

3„ General utility devices of greater capacities in Btorage and 
recognition units and more flexibility particularly with regard to 
sequencing of data. (DEMON'S, SLED) 

4. Elimination of bottlenecks at points such as editing, and key 
punching. 



I 

I 

I 

I 



- 139 - 





G HAND SYSTEMS 

I. IN TRO DUC TIO N. 

1. A great deal of intercepted traffic is of the so-called hand 
system type. This label covers a wide variety of systems but pri- 
marily describes those in which the encoding process involves a 
large amount of hand labor by the cipher clerk. Included are: 
monome-dinome substitution, multirlomic substitution employing a 
rectangle, transposition, multinomic code, literal code, and com- 
binations of these. A monome-dinome substitution is one wherein 
literal or numeric text is enciphered by means of a rectangle con- 
taining the alphabet and digits. The rectangle is bordered by numer- 
als. A text element is enciphered by selecting as cipher the border 
elements of the enciphering rectangle which locate the text element. 
Some rectangle elements are located by a single digit (monome), 
others by two digits (dinome). A multinomic ■ substitution employing 
a rectangle is one wherein plain text is enciphered in essentially the 
same mainner described above. Each text element is enciphered into 
a set of two or more digits, the number of digits being determined by 
the border of the enciphering rectangle. A transposition system is 
one wherein cipher text is obtained from plain text by reordering the 
plain text elements. As an example, plain text can be entered into a 
rectangle in the natural writing order (filling in row by row). If the 
plain text is then reordered by removing its elements from the rectangle 



- 140 - 




X XU 



PL 86-36/50 use 3605 
EO 3.3(h)(2) 

in a columnar fashion, the resulting text is a transposition of the 
original text. A multinomic code is a code wherein words and 
phrases of the plain text are given multinomic equivalents and are 
listed in a code book in numerical or alphabetic order. A multi- 
nomic code book may be thought of as a dictionary in which every 
word or phrase likely to occur in text is given a numeric equivalent 
(numeric meaning), and vice versa. A literal code is a code wherein 
words and phrases of the plain text are encoded by means of a set 
of letters according to a prescribed code book. 

2. Hand systems are often further complicated by the appli- 
cation of key which is usually either one -time -used, several -time- 
used, exploitable-phychological-random or exploitable -machine - 
non-random. 







PL 86-36/50 L 
EO 3.3(h)(2) 




II. DI AGNOST IC OP ERATIONS . 

1. Where messages appear which are neither plain text nor in 
some readily readable enciphering system, we must, in the absence 
of outside information, analyze the text of the message in order to 
determine the cryptosystem involved, 

2, The analysis of the messages can often be carried out by 

but for some of the 



hand for small systemd 



large systems described in the preceding section mechanization 
is required. Preliminary to an analysis of the text it must be 



edited, de -duped, and put on suitable medium such as IBM cards, 
perforated tape, etc. These three steps are at present outstanding 
bottlenecks in this and latdr stages of exploitation. For example, 
of the 10,000 hours per month of machine time 



3. The first step in the analysis is to attempt to identify the 
cryptosystem. Searches are performed to find exploitable intrinsic 
characteristics of plain language -3nd its encipherments. Examples 
are the widely varying frequencies at which the individual letters 
occur in literal text and the cohesion of plain language as exhibited 



- 142 - 



TOP SECRET EIDER 





1 LL/11 



by the rough frequency distribution of pqirs of letters (digraphs), 
triples of letters (trigraphs), etc. 

4, In Hand Systems where the enciphering process does not 
involve key (as examples, .monome -dinome substitution, codes, 
etc. ), diagnosis is often not too difficult. Hand analysis, standard 

IBM techniques and programs on general purpose computers pi_ g6 36/50 USC 3605 
(IBM's 701, Remington Rand's 1103) usually suffice. EO 3.3(h)(2) 




III. EXPLOITATION (Systems with no s uperencipherment by key) 

1. When a Hand System has been identified it is necessary to 
determine the parameters of the system so that messages can be 
decrypted 1 





I 

I 

I 



In this area there v is a need for desk aids which 
will lighten the clerical tasks performed by the analyst and help 
increase his output. 

!V. EXPLOITATI ON 








| 1. As stated in II. 2, editing, de -duping and hand punching and 

printing of traffic aye major problems in the preparation of text pre-> 

I liminary to analyses. To speed up these processes it is recommended 

| that more effort be placed on the mechanization of the editing and de- 

duping functions?. Hand punching and printing pose more difficult prob- 
| lems in that they are human operations which cannot be speeded up by 

I - 149 - 

I TOP SECRET EIDER - 










EO 3.3(h)(2) 

PL 86-36/50 USC 3605 



an Significiint,.f&ctor. However, the amount of hand punching required 
at NSA can be reduced by having traffic transmitted to NSA in a form 
suitable for machine handling and human analysis. 

2. Not stated in III. 2 is the problem of reading encoded messages 
when received as such or when any superencipherment has been stripped 
from code messages. When a major portion of the code book has been 
recovered, the problem reduces the looking up meanings. Code reading 
is being performed on MAISIE, a special purpose decoder. The 
MAISIE's are not handling this function adequately. A large amount of 
decoding must be performed on IBM due to MAISIE time not being avail- 
able. It is recommended 'that effort be placed on making the MAISIE's 
more reliable and more flexible. It is further recommended that the 
MAISIE's or their successors be designed to handle larger size code 
books . 

3. As stated in IV. 2 the processes involved in preliminary 
processing 



_ |are indeed a bottleneck in exploitation. However, these func- 

tions could adequately be performed on general data processing equip- 
ment such as the IBM-702 or on an equipment especially designed tp 
handle these and other functions (Farmer-Nomad study). 

4. As stated in V. 2 both general purpose computers and special 
purpose machines are employed in the principal processing of systems 
using exploitable key. General purpose computers are flexible enough 
to adequately perform many phases of this processing. However, com- 
puter time is at a premium and a definite need exists for more general 



- 150 - 




PL 86-36/50 USC 3605 
EO 3.3(h)(2) 

purpose devices. The SLEDS and DEMONS are also in great demddd. 

Man jobs are inefficiently performed on other pieces of equipment 
due to the non-availability of DEMON or SLED time. SLED is quite 
difficult to program and could be made more flexible. The DEMONS 
should be improved by a programmable and' 1 more flexible device 
which is widely applicable to the mechanisation of Agency problems. 




There is a definite need for equipment and personnel to make such 
runs when the information at hand warrants them. 



151 






1. Electrostatic and electromagnetic fields are associated with ■ 
the operation of electrical and electro-mecHanical devices. The 
radiation is caiused by changes in currents, sparking during switching, 
etc. In particular, unwanted radiation is usually associated with the 
operation of electrical cryptographic devices. This is due to the 
nature of operation of these devices, e.g. , the making and breaking 
of circuits in the device. Experience has indicated that our own 
cryptographic devices may radiate information which may compro- 
mise either the plain text or the machine. Every effort is being 
made to minimize unwanted radiation in our cryptographic devices. 





II. NOIS E COMMUNICATION 

1. A noise communication signal may be loosely defined as a 
signal that, when received on a typical amplitude modulation of fre- 
quency modulation receiver of standard design, has an output having 
characteristics simulating those which would be produced by an input 
(over a restricted bandwidth) of "white" noise. In other words, pro- 
vided the received energy from the noise signal is greater than the 
background noise of the receiver due to atmospheric noise and tube 
noise, an observer would suspect that he is listening to a pure noise 
generator being fed into the receiver. Noise communication is attrac- 
tive to communicators because it possesses both concealment 

Noise communication systems generally use some 
reproduCable form of "noise -like" signal as a carrier which is mod- 
ulated ay the intelligence signal. To a properly designed noise com- 
munications receiver and decoding mechanism, the output sounds like 
a good signal reasonably free from noise. However, the signal as 
picked up by an ordinary receiver would sound like ordinary noise. In 



- 153 .- 







- 154 - 




IV. G1PHONY. CIFAX AND SPEECH PRIVACY 



1. Introduction. 

1. a. Since communications are conveniently and rapidly 
carried out by means of telephony, it is natural for communica- 
tors who require secret communications to consider enciphering 
telephone conversations. The field involving making telephone 
communications secure is called ciphony (ciphered telephony). 
Examples of the need for enciphered* telephone conversation are 
the requirements of the aircraft pilots and high-ranking govern- 
ment officials who desire to make secure their conversations and 
transmit them directly to specific locations. or persons without de- 
lay or human intervention. Small beginnings of use of such systems 
occurred in World War II. NSA has developed several ciphony sys- 
tems and some of these are now under trial. • Quite wide application 
of ciphony seems probable in the not distant future. 

1. b. With the advent of facsimile transmissions, there came 
the need for making such transmissions secure. For example, a 
general (in the field) may wish to obtain by facsimile transmission 
from headquarters a copy- of a weather map showing the yreather con- 1 
ditions existing over the area under his command. A' copy of such a 
map would be invaluable to the enemy. To. avoid the occurrence of 
compromises, systems were^de'veldped which enciphered facsimile 
transmissions. This field of secret communications is called cifax 
(ciphered facsimile). 

- 156 - 






llTAYl 




J 



1* c. Speech privacy ie the term used to" denote speech sys-* * 
terns which afford their users only limited security. Speech privacy 
systems may employ either digital or non-digital methods of represent- 
ing the original speech signal. For illustrative purposes and for sim- 
plicity we shall restrict the discussion on speech privacy to non-digit&l 



speech security systems. 
2 . Ciphony and Cifax 



EO 3.3(h)(2) 

PL 86-36/50 USC 



2. a. Little attention has as yet been given to the problems of 
deriving COMINT from ciphony or cifax transmissions. I 




2. b. To produce a ciphony or cifax signal the original continuous' 
waveform or graphic material, respectively, is digitalized and then 
enciphered before transmission. Three methods of digitalization are 
currently in use: Delta -modulation (Delta-mod), Pulse Code Modu- 
lation (PCM), and Vocoder followed by PCM. 



- 157 - 



3. a. In non-digital speech security systems the speech signal 
is generally filtered through a set of band pass filters which divide 
the frequency spectrum of the signal into a set of adjacent frequency 
bands. The output of each band is a waveform whose frequency con- 
tent is limited by the band pass filter. To these outputs are added 
or subtracted signals of constant frequency. The frequencies of the 

I 

additive or subtractive signals are so chosen that the resultant fre*« 
quency bands exhaust the frequency bands of the original signals. 
Some of the frequency bands may be inverted during this process. 

The signals are then mixed to form a new signal which is transmitted 
as enciphered speech. 





Analysis of this type of system can be performed by comparison 



I 

I 

I 

I 



of the signal waveforms with known segments of voice waveforms. 
It is believed that from this type of analysis various kinds of split 
band systems with or without transposition and/or inversion of 
bands may be reconstructed. After such reconstruction, the inter- 
cepted signals become readily readable. 

Some consideration is being given to the desirability of devel- 
oping a flexible (with regard to number and size of bands, trans- 



position of bands, and inversion of bands), non-digital speech secur- 
ity intercept equipment. 

V. FACSIMILE INTERCEPT 



At the present time, the Agency is engaged in a relatively small 
facsimile intercept operation, there being only approximately 10 fac- 
simile intercept positions in operation. The systems currently being 
intercepted are not encrypted. Much of the intercepted traffic is 





recorded in the field on magnetic tape and forwarded to NSA Head- 
quarters for central processing, although a small amount is recorded 
on facsimile equipment in the field* 

The problem is not very difficult* but some mechanization can be 
effected to improve efficiency. At the moment* reproduction from 
the magnetic tape recordings at the Central Processing installation 
is subjected to distortion due to tape stretch and reproduction on a 
machine which, although of the same type as the recorder in the 
field* is slightly different due to normal engineering tolerances per- 
mitted in production. As a result, an operator must scan the fac- 
simile picture as it is being reproduced and attempt to compensate 
for the distortion by manual adjustments. R/D has recently developed 
a device for recording a reference tone on the magnetic tape in the 
field, and then automatically using this tone upon reproduction to com- 
pensate for the normal distortion. This equipment greatly reduces 
the burden on the operators and iB expected to result in a marked im- 
provement in the quality of the copy. 

The equipment can also be used in the field to supply a synchronizing 
tone for on-line processing. Fortunately, a limited number of reference 
synchronizing frequencies have been found to suffice for all known 
Russian Facsimile transmissions* and the exploitation of this feature' 
should facilitate high quality on-line processing in the field. This 
improved equipment is now being fabricated for service test by the 
services. It is anticipated that "crash production" of a limited number 



- 163 - 



of these equipments will enable the currently Employed facsimile 
positions to be converted by the end of the calendar year, while 
future facsimile 'positions should be equipped with equipments 
obtained through normal production channels. 

VI. VERY HIGH FREQUENCY INTERCEPT (VHF) 

The VHF/UHF problem has been broken into Categories I and 
II; the VHF problem as here discussed is essentially Category I, 
which is defined as follows: 

"CATEGORY I comprises problems which may generally be 
solved, at least in part, by the application of well-known techniques 
and currently available equipment types. Roughly speaking, Category 
I communications are of wide-spread types, often low-powered, tac- 
tical, omni-directional and of a state of sophistication common among 
communicators of the major nations. At present. Category I com- 
munications are predominantly MCW and unenciphered speech, with 
possible future speech privacy, ciphony and other more sophisticated 
systems as the growth of the art permits. Typical Category I com- 
munication services include air-air, air-ground, tank-tank, ship- 
ship, ship-shore and low echelon ground-ground. " 

Operationally, the VHF Category I problem is very important, 
with a strong and increasing AFSS effort and certain near -future 
expansion of small Army and Navy hear -VHF and VHF activities. 

At the present time, this problem is under study by the Special 
Intercept Problems Board. 



164 - 




PL 86-36/50 USC 3605 

EO 3.3(h)(2) 

* » 

■ At this writing, the equipment picture -in the near-VHF 
(20-30 mes) and the VHF (30-300 mes) is sad, with most 
service successes due to field initiative in doctoring available 
receivers and preparing special antennas* However, an improved, 
militarized receiver, the R-220 (also knovrti as the AN/URR-29 
when equipped' with antennas of no particular COMINT use) is sched- 
uled to come off the line in limited quantities before the end of calen- 
dar 1955 . While this receiver, which covers the range from 20 to 
250 mes, may fall considerably short of the ideal, its great superi- 
ority to older receivers in the field and the fact that it is under quan- 
tity procurement by all three of the service cryptologic agencies 
should soon bring a considerable strengthening of the Category I 
intercept effort. In the 100-150 mes. range, of prime importance 
to the Air Force and also of great Navy significance, a commercial 
receiver the Clarke 167J1 is applicable. This receiver, which has 
been the backbone of the AFSS effort for the last three years, will 
probably have even greater future usefulness. Antenna-wise, local 
initiative has been the major source of improvement. Although 




- 165 - 




At present, R/D is contiguously monitoring all military and 
commercial receiver and antenna developments which are applicable 
to this problem. Plans are under way to exploit the "hot" Clarke in 
an effort to provide maximum receiver sensitivity for special Cate- 
gory I problems. The "hot" Clarke is a standard Clarke 167J1 with 
an NRL developed low-noise preamplifier and any one of several 

l 

appropriate bandwidth reduction systems. 

Recently R/D has been authorized to establish two experimental 
field research and development positions on the VHF intercept prob- 
lem, one in the far East and the other in Europe. These units are 
expected to be activated before September 1955, and should enable 
experimental equipments and techniques to be evaluated and devel- 
oped under actual field conditions. 

Future R/D plans call for service testing of "hot" Clarke re- 
ceivers, and the development of panoramic receivers and adapters 
for use in the 100 to 150 mcs. range, where an operational require- 
ment has already been expressed by AFSS . The, study of antennas, 
such as the vertical rhombic developed by the Bureau of Standards, 
and the retention of commercial antenna consultants will aid in evenp 
tually bringing to the field antennas with maximum directivity. It is 
also intended to study rotators and towers to assure the field of an- 
tenna systems of maximum operational utility. It is intended to 
strengthen R/D Field Support through several activities; 



- 166 - 




(a) Continued and expanded field trips. 

(b) Establishment of a task type contract to provide a 
ready source of development equipment for the R/D 
Field Positions. 

(c) Establishment of a local experimental mobile van 
which will be used as a proving ground for equipment 
and techniques. To assure maximum understanding of 
propagation phenomena contacts have been made with 
NEL and CRPL of BuStandards. to determine what 
assistance they can provide for prediction in the VHF 
range; two outstanding CRPL men are now being 
cleared for COMINT so they can be brought into the 
entire problem. 

VII. ULTRA HIGH FREQUENCY INTERCEPT (UHF) 

The VHF/UHF problem has been broken into Categories I and II; 
the UHF problem, as here discussed, is essentially Category II, 
which is defined as follows: 

"CATEGORY II comprises special systems, often highly direc- 
tive with complicated multiplexing and high traffic densities used in 
relay type systems on a point-to-point basis; "High Level" traffic 
may appear inappreciable quantities on these systems. Category II 
represents technical and operational problems of a higher order of 
difficulty than those in Category I and, therefore, may require 



- 167 - 




PL 86-36/50 U 
EO 3.3(h)(2) 



research and development, special equipmenfand personnel for 
each new problem. " 









As in the case of VHF intercept, it is intended to strengthen 
the R/D Field Support through several activities: 

fa) Continued and expanded field trips. Further, a con- 
tract is being negotiated for a total of 6 field technical 
representatives. Although the* impetus for this "Tech 
Rep" program has come from the Category II, program*, 
these people will be used for other purposes, notably VHF 
Category I, as the occasion arises. 

(b) Establishment of a task type contract (to be shared with 
VHF) to provide a ready source of development equip- 
ment for the R/D field positions. 

(c) Establishment of a local van (to be shared with VHF) 
which will be used as, a proving ground for equipment 
and techniques. 

To assure maximum understanding of propagation phenomena, 
contacts have been made with NEL, and CRPL, of BuStandards, to 
determine what assistance they can provide for prediction in the UHF 
range: two outstanding CRPL men are now being cleared for COMINT 
so they can be brought into the entire problem. 

VIII. COMMENTS AND RECOMMENDATIONS 

1. The amount of R/D effort currently being placed on each of 
the problems associated with the generation or intercept of "other 
signals" is implied in the section discussing the signal. The problems 
are sufficiently diverse and important to recommend continuation of 

■ 



- 170 - 




3. The problem of detecting radiated plain text signals in the 
cipher signal is in some respects similar to the problem of detecting 
a signal in the presence of noise. Communication theorists are doing 
considerable work on the general signal detection problem. Only a 
limited amount of work is being done in the Agency. It is recommended 
that the Agency increase its present efforts in this problem. 

4. The analysis of non^digital speech security systems currently 
requires equipment capable of splitting and mixing frequency bands. 

At present very little R/D effort is being placed on the development of 
new techniques and equipments. It is recommended that more effort be 
placed on the problem. 

- 171 - 





5. The problems of decrypting sophisticated ciphony and 
cifax systems have, as yet, received preliminary consideration 
only. It is recommended that a plan be drawn up and approval 
sought, for a powerful attack on these problems. 



- 172 - 



